An asset owner is the person responsible for the protection, classification, and proper use of an information asset. This means accountability for the asset, not necessarily ownership in the legal sense.
ISO 27001 Clause 5.3 and Annex A control A.5.9 (Inventory of Information Assets) require that a responsible person is assigned to each asset. The asset owner decides on classification (A.5.12), approves access rights, and ensures the asset is correctly recorded in the inventory. In practice, this is typically the business-responsible manager — for a customer database, the head of sales; for an ERP system, the head of finance.