Data-to-impact translation is the governance step that converts access evidence into a decision-ready understanding of business risk. It connects classification, ownership, and obligation so security can explain why a file incident matters, not just that it happened.