top of page
group of people in a high rise building looking out of the window

THE GLOBAL REFERENCE MODEL FOR DIGITAL TRUST CAPABILITY

The Digital Trust Capability Framework is the globally aligned reference model for building, measuring and assuring Digital Trust across organisations. Developed by The Digital Trust Institute® (DTI®), the framework defines how Digital Trust capability is structured, deployed and governed in real-world environments.

It defines the core organisational capabilities required to build, operate, and assure Digital Trust - Governance, Risk Management, Cybersecurity, Data Protection, AI Management and Resilience.


Aligned to UK National Cyber Security Centre (NCSC) guidance, UK Information Commissioners Office (ICO), UK National Institute of Standards and Technology (NIST) CSF 2.0 and supporting Special Publications, ISO/IEC standards, and the DTSp® professional pathways, it is the global reference model for Digital Trust capability, workforce development, and career progression.

Digital Trust Capability Framework

The Digital Trust Capability Framework defines the organisational capabilities required to build, operate, and assure Digital Trust across modern digital environments. It provides a globally aligned, standards‑based structure that integrates governance, risk, cybersecurity, data protection, AI management, and resilience into a unified discipline.

The Framework underpins the Digital Trust Specialist (DTSp®) pathways and aligns to:

  • UK NCSC governance and assurance principles

  • NIST CSF 2.0, NIST AI RMF and associated Special Publications

  • ISO/IEC 27001, 27701, 42001, 31000, 22301

  • ENISA, OECD, and global digital governance guidance

It is the capability model for the Digital Trust Profession and the Digital Trust Body of Knowledge™ (DTBoK™).

Purpose of the Framework

The Framework exists to:

  • define the capabilities required for trustworthy digital operations

  • provide a standards‑aligned structure for organisations

  • support professional pathways and specialist certification

  • enable assurance, measurement, and maturity assessment

  • unify governance, risk, cybersecurity, privacy, AI, and resilience

  • provide a common language for Digital Trust

The Framework is distinguished by:

  • alignment to national guidance and international standards

  • deployment within high-assurance environments

  • integration with professional credential pathways

  • applicability across multiple sectors and jurisdictions

This ensures that Digital Trust is defined consistently, across organisations, industries and geographies. It is the reference model for building Digital Trust capability at scale.

The Digital Trust Capability Domains

1. Governance

Governance establishes the leadership, accountability, and oversight structures that ensure digital systems are operated responsibly, transparently, and in alignment with organisational purpose and regulatory expectations.

Includes:

  • NCSC governance principles

  • NIST CSF “Govern” function

  • ISO/IEC 38500 digital governance

  • AI governance and oversight

  • Ethical and organisational integrity

Governance is the anchor capability for Digital Trust.

2. Risk Management

Risk Management ensures that digital, cyber, privacy, AI, and operational risks are identified, assessed, prioritised, and treated in a consistent, evidence‑based manner.

Includes:

  • ISO 31000

  • NIST CSF risk practices

  • Data protection risk (DPIAs)

  • NCSC Risk Management Framework

  • AI risk (NIST AI RMF, EU AI Act)

  • Supply chain and systemic risk

Risk Management is the decision‑making engine of Digital Trust.

3. Cybersecurity

Cybersecurity protects systems, data, and services from compromise and ensures the confidentiality, integrity, and availability of digital operations.

Includes:

  • NIST CSF 2.0

  • NCSC CAF

  • ISO/IEC 27001

  • Zero Trust architecture

  • Threat detection and response

Cybersecurity is the technical foundation of Digital Trust.

4. Data Protection

Data Protection ensures the lawful, ethical, and transparent handling of personal and sensitive data, respecting individuals’ rights and expectations.

Includes:

  • GDPR

  • UK ICO guidance

  • ISO/IEC 27701

  • Data minimisation and stewardship

  • Privacy engineering

  • Data ethics and transparency

Data Protection is the human‑rights layer of Digital Trust.

5. AI Management

AI Management ensures that AI systems are safe, fair, explainable, robust, and governed throughout their lifecycle.

Includes:

  • NIST AI RMF

  • ISO/IEC 42001

  • EU AI Act governance principles

  • Model assurance and transparency

  • Algorithmic risk and bias mitigation

AI Management is the future‑critical capability of Digital Trust.

6. Resilience

Resilience ensures that digital services can withstand, respond to, and recover from disruptions, maintaining trust even under stress.

Includes:

  • ISO 22301

  • NIST CSF “Respond” and “Recover”

  • Incident management

  • Business continuity

  • Crisis communication and trust restoration

Resilience is the continuity and recovery layer of Digital Trust.

 

How Organisations Use the Framework

The Framework supports:

  • Capability building across all six domains

  • Workforce development through DTSp® pathways

  • Risk‑based decision‑making

  • Assurance and audit

  • Procurement and supplier oversight

  • Digital transformation and AI adoption

  • Regulatory alignment

 

It is designed for use across:

  • public sector

  • defence and national security

  • critical national infrastructure

  • financial services

  • healthcare

  • technology and AI companies

 

Relationship to DTI® Credentials

The Digital Trust Capability Framework underpins the DTI professional ecosystem:

  • DTP® - aligned to UK NCSC guidance for governance and leadership capability

  • NCSP® - aligned to NIST CSF 2.0 and Special Publications for cybersecurity aligned operational capability

  • DTSp® - Integrated DTP, NCSP and ISO workforce and personal development pathways for specialist level capability

 

It provides the competency structure for:

  • role profiles

  • learning pathways

  • examinations

  • post‑nominals

  • CPD requirements

  • organisational membership

This ensures that Digital Trust is not only defined, but operationalised through structured, scalable credential pathways.

 

Why The Digital Trust Capability Framework Matters

Digital Trust is now a board‑level requirement and a regulatory expectation. The Framework provides:

  • a unified model for a fragmented domain

  • a standards‑aligned structure for organisations

  • a profession‑defining capability map

  • a foundation for global Digital Trust assurance

It is the canonical reference model for Digital Trust capability.

bottom of page