
THE GLOBAL REFERENCE MODEL FOR DIGITAL TRUST CAPABILITY
The Digital Trust Capability Framework is the globally aligned reference model for building, measuring and assuring Digital Trust across organisations. Developed by The Digital Trust Institute® (DTI®), the framework defines how Digital Trust capability is structured, deployed and governed in real-world environments.
It defines the core organisational capabilities required to build, operate, and assure Digital Trust - Governance, Risk Management, Cybersecurity, Data Protection, AI Management and Resilience.
Aligned to UK National Cyber Security Centre (NCSC) guidance, UK Information Commissioners Office (ICO), UK National Institute of Standards and Technology (NIST) CSF 2.0 and supporting Special Publications, ISO/IEC standards, and the DTSp® professional pathways, it is the global reference model for Digital Trust capability, workforce development, and career progression.
Digital Trust Capability Framework
The Digital Trust Capability Framework defines the organisational capabilities required to build, operate, and assure Digital Trust across modern digital environments. It provides a globally aligned, standards‑based structure that integrates governance, risk, cybersecurity, data protection, AI management, and resilience into a unified discipline.
The Framework underpins the Digital Trust Specialist (DTSp®) pathways and aligns to:
-
UK NCSC governance and assurance principles
-
NIST CSF 2.0, NIST AI RMF and associated Special Publications
-
ISO/IEC 27001, 27701, 42001, 31000, 22301
-
ENISA, OECD, and global digital governance guidance
It is the capability model for the Digital Trust Profession and the Digital Trust Body of Knowledge™ (DTBoK™).
Purpose of the Framework
The Framework exists to:
-
define the capabilities required for trustworthy digital operations
-
provide a standards‑aligned structure for organisations
-
support professional pathways and specialist certification
-
enable assurance, measurement, and maturity assessment
-
unify governance, risk, cybersecurity, privacy, AI, and resilience
-
provide a common language for Digital Trust
The Framework is distinguished by:
-
alignment to national guidance and international standards
-
deployment within high-assurance environments
-
integration with professional credential pathways
-
applicability across multiple sectors and jurisdictions
This ensures that Digital Trust is defined consistently, across organisations, industries and geographies. It is the reference model for building Digital Trust capability at scale.
The Digital Trust Capability Domains
1. Governance
Governance establishes the leadership, accountability, and oversight structures that ensure digital systems are operated responsibly, transparently, and in alignment with organisational purpose and regulatory expectations.
Includes:
-
NCSC governance principles
-
NIST CSF “Govern” function
-
ISO/IEC 38500 digital governance
-
AI governance and oversight
-
Ethical and organisational integrity
Governance is the anchor capability for Digital Trust.
2. Risk Management
Risk Management ensures that digital, cyber, privacy, AI, and operational risks are identified, assessed, prioritised, and treated in a consistent, evidence‑based manner.
Includes:
-
ISO 31000
-
NIST CSF risk practices
-
Data protection risk (DPIAs)
-
NCSC Risk Management Framework
-
AI risk (NIST AI RMF, EU AI Act)
-
Supply chain and systemic risk
Risk Management is the decision‑making engine of Digital Trust.
3. Cybersecurity
Cybersecurity protects systems, data, and services from compromise and ensures the confidentiality, integrity, and availability of digital operations.
Includes:
-
NIST CSF 2.0
-
NCSC CAF
-
ISO/IEC 27001
-
Zero Trust architecture
-
Threat detection and response
Cybersecurity is the technical foundation of Digital Trust.
4. Data Protection
Data Protection ensures the lawful, ethical, and transparent handling of personal and sensitive data, respecting individuals’ rights and expectations.
Includes:
-
GDPR
-
UK ICO guidance
-
ISO/IEC 27701
-
Data minimisation and stewardship
-
Privacy engineering
-
Data ethics and transparency
Data Protection is the human‑rights layer of Digital Trust.
5. AI Management
AI Management ensures that AI systems are safe, fair, explainable, robust, and governed throughout their lifecycle.
Includes:
-
NIST AI RMF
-
ISO/IEC 42001
-
EU AI Act governance principles
-
Model assurance and transparency
-
Algorithmic risk and bias mitigation
AI Management is the future‑critical capability of Digital Trust.
6. Resilience
Resilience ensures that digital services can withstand, respond to, and recover from disruptions, maintaining trust even under stress.
Includes:
-
ISO 22301
-
NIST CSF “Respond” and “Recover”
-
Incident management
-
Business continuity
-
Crisis communication and trust restoration
Resilience is the continuity and recovery layer of Digital Trust.
How Organisations Use the Framework
The Framework supports:
-
Capability building across all six domains
-
Workforce development through DTSp® pathways
-
Risk‑based decision‑making
-
Assurance and audit
-
Procurement and supplier oversight
-
Digital transformation and AI adoption
-
Regulatory alignment
It is designed for use across:
-
public sector
-
defence and national security
-
critical national infrastructure
-
financial services
-
healthcare
-
technology and AI companies
Relationship to DTI® Credentials
The Digital Trust Capability Framework underpins the DTI professional ecosystem:
-
DTP® - aligned to UK NCSC guidance for governance and leadership capability
-
NCSP® - aligned to NIST CSF 2.0 and Special Publications for cybersecurity aligned operational capability
-
DTSp® - Integrated DTP, NCSP and ISO workforce and personal development pathways for specialist level capability
It provides the competency structure for:
-
role profiles
-
learning pathways
-
examinations
-
post‑nominals
-
CPD requirements
-
organisational membership
This ensures that Digital Trust is not only defined, but operationalised through structured, scalable credential pathways.
Why The Digital Trust Capability Framework Matters
Digital Trust is now a board‑level requirement and a regulatory expectation. The Framework provides:
-
a unified model for a fragmented domain
-
a standards‑aligned structure for organisations
-
a profession‑defining capability map
-
a foundation for global Digital Trust assurance
It is the canonical reference model for Digital Trust capability.
