diff --git a/controls/operations/reporting/OPS.REP.003_security_roles_and_responsibilities.md b/controls/operations/reporting/OPS.REP.003_security_roles_and_responsibilities.md
new file mode 100644
index 000000000..d22a278ed
--- /dev/null
+++ b/controls/operations/reporting/OPS.REP.003_security_roles_and_responsibilities.md
@@ -0,0 +1,31 @@
+---
+id: "OPS-REP-003"
+category: "operations/reporting"
+revision-version: 1
+revision-date: "2024-01-13"
+estimate-time: "15m"
+frameworks:
+ - name: "soc2"
+ sections: ["CC1.2", "CC1.3", "CC1.5", "CC2.2", "CC4.3"]
+---
+
+## Purpose
+
+Having clear ownership improve accountability, it helps employees
+figure out what is legit and what is not.
+
+## Implementation
+
+Here is the kind of document expected - it has to be done for every
+role with a potential impact on security:
+
+| Role | Responsibilities |
+|------|-----------------|
+| CTO | • Oversees the overall security architecture and ensures that the technology stack aligns with security best practices
• Implements and enforces security policies across all engineering teams
• Ensures the security of the company's API by leading security audits, vulnerability assessments, and patch management
• Coordinates the implementation of access controls, encryption protocols, and incident response procedures |
+| Engineers | • Maintain the confidentiality, integrity, and availability of the information systems and processes for which they are responsible in compliance with COMPANY policies on information security and privacy
• Responsible for the development and deployment of secure code in accordance with COMPANY standards, policies, and procedures
• Leader of the Incident Response team, responsible for incident response, documentation, and lessons learned process
• Execution of customer data retention and deletion processes in accordance with company policy and customer requirements |
+| Head of People | • Ensures that employee onboarding and offboarding processes adhere to security protocols, including access control to company systems
• Collaborates with the IT team to manage employee access to sensitive information and ensure role-based access control
• Develops and maintains security-related HR policies, such as security awareness training, background checks, and confidentiality agreements |
+| Office and events manager | • Manages the issuance, tracking, and return of company equipment (laptops, phones) with security policies in place
• Manages access for new joiners and leavers for all general software and platforms
• Collaborates with CTO to ensure proper deactivation of devices when employees leave or change roles
• Tracks and audits equipment inventory to prevent unauthorized access to company systems or data |
+
+## Evidence
+
+- Screenshot of your page where those responsibilities are shared.