Internal Privacy Audit Program
Overview
An internal privacy audit program provides systematic, independent assurance that an organization's privacy practices conform to applicable data protection regulations, internal policies, contractual obligations, and recognized frameworks. Unlike external audits (SOC 2, ISO 27701 certification), internal privacy audits are conducted by or on behalf of the organization itself, giving management direct visibility into compliance gaps before they become regulatory findings or breaches.
The internal privacy audit function operates under the IIA (Institute of Internal Auditors) International Standards for the Professional Practice of Internal Auditing and adapts these standards to the privacy domain. At Sentinel Compliance Group, the internal privacy audit program reports to the Audit Committee of the Board of Directors, maintaining independence from the privacy operations function it audits.
Audit Universe Definition
The privacy audit universe represents the complete set of auditable entities, processes, and systems relevant to privacy compliance. It forms the basis for risk-based audit planning.
Privacy Audit Universe Categories
| Category |
Auditable Areas |
Example Entities |
| Regulatory Compliance |
GDPR, CCPA/CPRA, LGPD, PIPA, sector-specific laws |
EU processing operations, California consumer data handling, Brazilian customer data |
| Data Lifecycle |
Collection, processing, storage, sharing, retention, deletion |
Web forms, CRM system, data warehouse, third-party APIs, backup systems |
| Data Subject Rights |
Access, rectification, erasure, portability, restriction, objection |
DSAR intake process, identity verification, response workflow, automated systems |
| Third-Party Management |
Processors, sub-processors, joint controllers, data sharing |
Cloud hosting, analytics vendors, marketing platforms, payment processors |
| Privacy Governance |
Policies, training, DPO function, privacy committee, DPIA process |
Privacy policy management, training program, DPO independence, DPIA register |
| Technical Controls |
Encryption, access controls, pseudonymization, logging, deletion |
Database encryption, IAM configuration, log management, automated purge jobs |
| Breach Management |
Detection, assessment, notification, documentation, remediation |
SIEM configuration, breach assessment process, DPA notification, root cause analysis |
| Cross-Border Transfers |
Transfer mechanisms, TIAs, supplementary measures |
SCCs, BCRs, adequacy decisions, data localization controls |
| Consent Management |
Collection, recording, withdrawal, preference management |
Consent platforms, cookie banners, preference centers, consent databases |
| Records of Processing |
RoPA completeness, accuracy, maintenance |
Controller register, processor register, update workflow |
Risk-Based Prioritization
Each auditable area is scored on a risk matrix:
| Risk Factor |
Weight |
Scoring (1-5) |
| Regulatory exposure |
25% |
1 = No regulation, 5 = Multiple strict regulations with active enforcement |
| Volume of personal data |
20% |
1 = Minimal PII, 5 = Large-scale special category data |
| Prior audit findings |
15% |
1 = No findings, 5 = Unresolved critical findings |
| Organizational change |
15% |
1 = Stable, 5 = Major system/process changes |
| Third-party dependency |
10% |
1 = No third parties, 5 = Critical third-party processing |
| Complaint/incident history |
10% |
1 = No incidents, 5 = Multiple privacy incidents |
| Time since last audit |
5% |
1 = Audited this quarter, 5 = Never audited or >2 years |
Risk Score Calculation: Weighted sum of all factors (maximum 5.0)
| Risk Score |
Audit Frequency |
| 4.0 — 5.0 |
Every 6 months |
| 3.0 — 3.9 |
Annual |
| 2.0 — 2.9 |
Every 18 months |
| 1.0 — 1.9 |
Every 24 months or as resources permit |
Annual Audit Plan
Plan Development Process
- Update Audit Universe (Q4 of preceding year): Review the audit universe for new systems, regulations, processing activities, and organizational changes
- Conduct Risk Assessment (Q4): Score each auditable area using the risk matrix above
- Allocate Resources (Q4): Determine available audit hours based on team size and skill sets
- Draft Annual Plan (Q4): Schedule audits by quarter, balancing risk priority with resource availability and organizational calendar constraints
- Management Approval (Q4): Present the annual audit plan to the Audit Committee for approval
- Quarterly Review (each quarter): Adjust the plan based on emerging risks, regulatory changes, or management requests
Annual Plan Template
Sentinel Compliance Group — Privacy Audit Annual Plan 2025
Approved By: Audit Committee, December 15, 2024
Plan Owner: Chief Audit Executive
Q1 2025:
- DSAR Response Process (Risk Score: 4.3, Last Audit: Jun 2024)
- Cookie Consent Management (Risk Score: 3.8, Last Audit: Mar 2024)
Q2 2025:
- Third-Party Processor Management (Risk Score: 4.5, Last Audit: Dec 2023)
- Cross-Border Data Transfers (Risk Score: 4.1, Last Audit: Sep 2024)
Q3 2025:
- Data Retention and Deletion (Risk Score: 3.9, Last Audit: Jun 2024)
- Privacy Training Effectiveness (Risk Score: 3.2, Last Audit: Dec 2024)
Q4 2025:
- Breach Notification Process (Risk Score: 4.0, Last Audit: Mar 2024)
- Records of Processing Activities (Risk Score: 3.5, Last Audit: Sep 2024)
Reserve/Contingency (50 hours):
- Ad hoc investigations, management requests, regulatory-triggered audits
Audit Execution Phases
Phase 1: Planning and Scoping (1-2 Weeks)
1.1 Audit Charter Confirmation
Confirm that the internal audit charter authorizes privacy audits and defines:
- Audit authority and independence
- Access to records, personnel, and systems
- Reporting relationships
- Confidentiality obligations of audit staff
1.2 Preliminary Research
- Review applicable regulations and recent enforcement actions
- Review prior audit reports and outstanding findings
- Review recent privacy incidents, complaints, and DSAR metrics
- Review organizational changes affecting the audit scope
- Review regulatory guidance and supervisory authority publications
1.3 Scope Definition
Document the audit scope including:
| Scope Element |
Description |
| Objective |
What the audit intends to evaluate (e.g., adequacy and effectiveness of DSAR response controls) |
| Period |
The timeframe under examination (e.g., January 1 — June 30, 2025) |
| Entities |
Organizational units in scope |
| Systems |
IT systems and platforms in scope |
| Regulations |
Applicable legal requirements |
| Standards |
Applicable internal policies and external frameworks |
| Exclusions |
Explicitly out-of-scope areas with justification |
1.4 Audit Program Development
Create the detailed audit program (test procedures) for each control objective:
Control Objective: DSARs are processed within regulatory timeframes
Test 1: Obtain DSAR tracking log for the audit period
Test 2: Select sample of [n] DSARs per sampling methodology
Test 3: For each sampled DSAR, verify:
a. Identity verification was completed before disclosure
b. Response was provided within 30 days (GDPR) or 45 days (CCPA)
c. Response contained all required information per Art. 15
d. Extension, if used, was communicated within initial deadline
e. Denial, if applicable, was justified and communicated with appeal rights
Test 4: Review DSAR metrics for trend analysis
Test 5: Interview DSAR coordinators on process adherence
1.5 Engagement Letter
Issue the engagement letter to the audit client (privacy operations team) containing:
- Audit objective and scope
- Audit period
- Expected fieldwork dates
- Information and access requirements
- Key contacts
- Preliminary meeting schedule
Phase 2: Fieldwork (2-4 Weeks)
2.1 Opening Meeting
Conduct an opening meeting with the audit client to:
- Confirm scope and timing
- Identify key contacts for each area
- Discuss logistics (room access, system access, document sharing)
- Address any concerns or constraints
2.2 Evidence Gathering Techniques
| Technique |
Application |
Example |
| Document Review |
Policies, procedures, records, reports |
Review privacy policy against GDPR Art. 13-14 requirements |
| Interview |
Process understanding, control awareness |
Interview DPO on DPIA review process |
| Observation |
Process walkthrough, system demonstration |
Observe DSAR fulfillment from intake to response |
| Data Analysis |
Population analysis, trend identification, anomaly detection |
Analyze DSAR response times across the full population |
| Technical Testing |
System configuration verification |
Verify encryption-at-rest configuration on database |
| Sampling |
Representative testing of transactions |
Select 30 DSARs from population of 450 for detailed testing |
| Reperformance |
Independent control execution |
Submit test DSAR and verify correct handling |
2.3 Sampling Methodology
Internal privacy audit sampling follows IIA Practice Guide "Audit Sampling":
Attribute Sampling (for compliance testing):
| Population Size |
Expected Error Rate |
95% Confidence Sample |
| 50-100 |
0% expected |
30 |
| 101-500 |
0% expected |
40 |
| 501-1000 |
0% expected |
50 |
| 1000+ |
0% expected |
60 |
| Any |
1-5% expected |
Add 10-20 to above |
Judgmental Sampling (risk-focused selection):
- High-value transactions (DSARs involving sensitive data)
- Edge cases (DSARs with extensions, partial denials, cross-border elements)
- Time-based distribution (ensure coverage across the entire audit period)
- New process implementation (overweight periods after process changes)
2.4 Working Paper Standards
Every audit test must be documented in working papers containing:
| Working Paper Element |
Description |
| Reference Number |
Unique identifier linked to the audit program test step |
| Objective |
What the test is designed to evaluate |
| Procedure |
Detailed steps performed |
| Population |
Description and size of the population tested |
| Sample |
Size and selection methodology |
| Results |
Factual findings for each sample item |
| Conclusion |
Pass/Fail determination with reasoning |
| Evidence |
Attached or cross-referenced supporting documentation |
| Preparer |
Auditor name and date |
| Reviewer |
Reviewer name and date |
Phase 3: Finding Classification and Reporting (1-2 Weeks)
3.1 Finding Classification
Each finding is classified by severity:
| Severity |
Criteria |
Response Time |
| Critical |
Systemic non-compliance with regulation; imminent risk of enforcement action, significant data breach, or harm to data subjects; complete control failure |
Immediate: interim remediation within 5 business days; full remediation within 30 days |
| High |
Material non-compliance; control design deficiency or widespread operating failure; significant gap between policy and practice |
Remediation plan within 10 business days; full remediation within 60 days |
| Medium |
Isolated non-compliance; control operating inconsistently; documentation gaps that could lead to material issues |
Remediation within 90 days |
| Low |
Minor documentation gaps; process improvement opportunities; control enhancements that would strengthen compliance posture |
Remediation within 180 days |
| Advisory |
Best practice recommendations; emerging risk observations; no current non-compliance |
No required response; tracked for information |
3.2 Finding Structure
Each finding is documented using the Condition-Criteria-Cause-Consequence-Recommendation format:
Finding ID: PA-2025-Q2-003
Title: Incomplete identity verification for DSAR fulfillment
Severity: High
Status: Open
Condition (What did we find?):
In 6 of 30 sampled DSARs (20%), the identity verification step was not
completed or documented prior to disclosing personal data to the requestor.
Affected requests: DSAR-2025-0147, DSAR-2025-0203, DSAR-2025-0289,
DSAR-2025-0312, DSAR-2025-0378, DSAR-2025-0401.
Criteria (What should be happening?):
GDPR Art. 12(6) requires controllers to verify the identity of the data
subject making the request, particularly where the controller has reasonable
doubts. Sentinel Compliance Group Privacy Procedure PR-DSAR-001 Section 4.2
requires two-factor identity verification for all DSARs before any personal
data is disclosed.
Cause (Why did it happen?):
The DSAR workflow system does not enforce a mandatory verification step before
allowing the coordinator to mark the request as "in progress." Three of the
six cases involved requests received via email rather than the self-service
portal, where the verification workflow is not automated.
Consequence (What is the risk?):
Without proper identity verification, personal data may be disclosed to
unauthorized individuals, constituting a personal data breach under Art. 4(12)
GDPR. This could result in supervisory authority enforcement action, reputational
harm, and direct harm to data subjects. The ICO fined a UK company GBP 175,000
in 2023 for disclosing personal data in response to a fraudulent DSAR.
Recommendation:
1. Implement a mandatory verification gate in the DSAR workflow system that
blocks progression until verification is completed and documented.
2. Extend automated verification to email-originated DSARs by redirecting
requestors to the self-service portal.
3. Retrain DSAR coordinators on verification requirements.
Management Response: [To be completed by management]
Remediation Owner: [To be assigned]
Target Date: [To be set]
3.3 Audit Report Structure
INTERNAL PRIVACY AUDIT REPORT
Report Number: PA-2025-Q2
Classification: Confidential
1. Executive Summary
- Audit objective and scope
- Overall rating (Satisfactory / Needs Improvement / Unsatisfactory)
- Summary of findings by severity
- Key themes and systemic issues
2. Audit Scope and Approach
- Detailed scope description
- Regulations and standards tested against
- Methodology (sampling, testing approach)
- Period covered
- Limitations and constraints
3. Findings and Recommendations
- Critical findings (if any)
- High findings
- Medium findings
- Low findings
- Advisory observations
4. Management Action Plans
- Agreed remediation actions per finding
- Responsible owners
- Target completion dates
5. Prior Audit Follow-Up
- Status of findings from prior audits
- Closed findings with verification evidence
- Overdue findings with escalation status
6. Appendices
- Detailed test results
- Population and sample details
- Documents reviewed
- Personnel interviewed
3.4 Overall Audit Rating
| Rating |
Criteria |
| Satisfactory |
No critical or high findings; medium and low findings do not indicate systemic issues; controls are generally effective |
| Needs Improvement |
One or more high findings OR multiple medium findings indicating a pattern; controls are partially effective but require strengthening |
| Unsatisfactory |
One or more critical findings OR multiple high findings; fundamental control failures exist; immediate management attention required |
Phase 4: Remediation Tracking (Ongoing)
4.1 Remediation Lifecycle
Finding Issued → Management Response (10 business days) → Remediation In Progress
→ Owner Reports Completion → Audit Verification Testing → Finding Closed OR
→ Reopened with Revised Plan
4.2 Tracking Dashboard
| Metric |
Measurement |
| Open Findings by Severity |
Count of open findings per critical/high/medium/low |
| Overdue Findings |
Count and percentage of findings past target date |
| Average Time to Remediate |
Mean days from finding issuance to verified closure |
| Remediation Effectiveness |
Percentage of findings closed on first attempt (not reopened) |
| Recurrence Rate |
Percentage of findings that reappear in subsequent audits |
4.3 Escalation Protocol
| Condition |
Escalation Level |
| Critical finding not addressed within 5 business days |
Chief Privacy Officer and CISO |
| High finding overdue by 30+ days |
Chief Audit Executive to Audit Committee |
| Medium finding overdue by 60+ days |
Chief Audit Executive to management |
| Pattern of repeated findings in same area |
Chief Audit Executive to Audit Committee |
| Management refuses to remediate |
Chief Audit Executive to Audit Committee and Board |
Phase 5: Management Reporting (Quarterly)
5.1 Quarterly Privacy Audit Report to Audit Committee
- Summary of audits completed in the quarter
- Summary of findings by severity and theme
- Remediation progress dashboard
- Emerging privacy risks identified
- Annual audit plan status and any proposed adjustments
- Resource utilization and any capacity constraints
5.2 Annual Privacy Audit Summary
- All audits completed during the year
- Trend analysis of findings across the year
- Assessment of the organization's overall privacy posture
- Comparison to prior year
- Recommendations for the following year's audit plan
- Lessons learned and methodology improvements
Sentinel Compliance Group Internal Privacy Audit Program
Sentinel Compliance Group operates an internal privacy audit program with the following characteristics:
- Team: Two dedicated privacy auditors plus one co-sourced external privacy audit specialist
- Annual Audit Hours: 1,200 hours allocated to privacy audits
- Audits Per Year: 8-10 privacy audits plus continuous monitoring activities
- Reporting Line: Chief Audit Executive reports to the Audit Committee; privacy audit results shared with the DPO
- Tools: AuditBoard for working papers and finding management; ServiceNow for remediation tracking
- 2024 Results: 9 audits completed, 47 findings issued (2 critical, 8 high, 22 medium, 15 low), 89% remediation rate within target dates, overall privacy posture rated "Needs Improvement" trending toward "Satisfactory"
1---2name: internal-privacy-audit3description: Guides internal privacy audit program design and execution including risk-based audit planning, scope definition, fieldwork procedures, finding classification, evidence gathering, remediation tracking, and management reporting. Covers audit universe definition, annual audit plan, working papers, and closure verification. Keywords: internal audit, privacy audit, fieldwork, remediation, findings, audit plan.4license: Apache-2.05---6# Internal Privacy Audit Program
7
8## Overview
9
10An internal privacy audit program provides systematic, independent assurance that an organization's privacy practices conform to applicable data protection regulations, internal policies, contractual obligations, and recognized frameworks. Unlike external audits (SOC 2, ISO 27701 certification), internal privacy audits are conducted by or on behalf of the organization itself, giving management direct visibility into compliance gaps before they become regulatory findings or breaches.
11
12The internal privacy audit function operates under the IIA (Institute of Internal Auditors) International Standards for the Professional Practice of Internal Auditing and adapts these standards to the privacy domain. At Sentinel Compliance Group, the internal privacy audit program reports to the Audit Committee of the Board of Directors, maintaining independence from the privacy operations function it audits.
13
14## Audit Universe Definition
15
16The privacy audit universe represents the complete set of auditable entities, processes, and systems relevant to privacy compliance. It forms the basis for risk-based audit planning.
17
18### Privacy Audit Universe Categories
19
20| Category | Auditable Areas | Example Entities |
21|----------|----------------|------------------|
22| Regulatory Compliance | GDPR, CCPA/CPRA, LGPD, PIPA, sector-specific laws | EU processing operations, California consumer data handling, Brazilian customer data |
23| Data Lifecycle | Collection, processing, storage, sharing, retention, deletion | Web forms, CRM system, data warehouse, third-party APIs, backup systems |
24| Data Subject Rights | Access, rectification, erasure, portability, restriction, objection | DSAR intake process, identity verification, response workflow, automated systems |
25| Third-Party Management | Processors, sub-processors, joint controllers, data sharing | Cloud hosting, analytics vendors, marketing platforms, payment processors |
26| Privacy Governance | Policies, training, DPO function, privacy committee, DPIA process | Privacy policy management, training program, DPO independence, DPIA register |
27| Technical Controls | Encryption, access controls, pseudonymization, logging, deletion | Database encryption, IAM configuration, log management, automated purge jobs |
28| Breach Management | Detection, assessment, notification, documentation, remediation | SIEM configuration, breach assessment process, DPA notification, root cause analysis |
29| Cross-Border Transfers | Transfer mechanisms, TIAs, supplementary measures | SCCs, BCRs, adequacy decisions, data localization controls |
30| Consent Management | Collection, recording, withdrawal, preference management | Consent platforms, cookie banners, preference centers, consent databases |
31| Records of Processing | RoPA completeness, accuracy, maintenance | Controller register, processor register, update workflow |
32
33### Risk-Based Prioritization
34
35Each auditable area is scored on a risk matrix:
36
37| Risk Factor | Weight | Scoring (1-5) |
38|-------------|--------|----------------|
39| Regulatory exposure | 25% | 1 = No regulation, 5 = Multiple strict regulations with active enforcement |
40| Volume of personal data | 20% | 1 = Minimal PII, 5 = Large-scale special category data |
41| Prior audit findings | 15% | 1 = No findings, 5 = Unresolved critical findings |
42| Organizational change | 15% | 1 = Stable, 5 = Major system/process changes |
43| Third-party dependency | 10% | 1 = No third parties, 5 = Critical third-party processing |
44| Complaint/incident history | 10% | 1 = No incidents, 5 = Multiple privacy incidents |
45| Time since last audit | 5% | 1 = Audited this quarter, 5 = Never audited or >2 years |
46
47**Risk Score Calculation**: Weighted sum of all factors (maximum 5.0)
48
49| Risk Score | Audit Frequency |
50|-----------|-----------------|
51| 4.0 — 5.0 | Every 6 months |
52| 3.0 — 3.9 | Annual |
53| 2.0 — 2.9 | Every 18 months |
54| 1.0 — 1.9 | Every 24 months or as resources permit |
55
56## Annual Audit Plan
57
58### Plan Development Process
59
601. **Update Audit Universe** (Q4 of preceding year): Review the audit universe for new systems, regulations, processing activities, and organizational changes
612. **Conduct Risk Assessment** (Q4): Score each auditable area using the risk matrix above
623. **Allocate Resources** (Q4): Determine available audit hours based on team size and skill sets
634. **Draft Annual Plan** (Q4): Schedule audits by quarter, balancing risk priority with resource availability and organizational calendar constraints
645. **Management Approval** (Q4): Present the annual audit plan to the Audit Committee for approval
656. **Quarterly Review** (each quarter): Adjust the plan based on emerging risks, regulatory changes, or management requests
66
67### Annual Plan Template
68
69```
70Sentinel Compliance Group — Privacy Audit Annual Plan 2025
71
72Approved By: Audit Committee, December 15, 2024
73Plan Owner: Chief Audit Executive
74
75Q1 2025:
76 - DSAR Response Process (Risk Score: 4.3, Last Audit: Jun 2024)
77 - Cookie Consent Management (Risk Score: 3.8, Last Audit: Mar 2024)
78
79Q2 2025:
80 - Third-Party Processor Management (Risk Score: 4.5, Last Audit: Dec 2023)
81 - Cross-Border Data Transfers (Risk Score: 4.1, Last Audit: Sep 2024)
82
83Q3 2025:
84 - Data Retention and Deletion (Risk Score: 3.9, Last Audit: Jun 2024)
85 - Privacy Training Effectiveness (Risk Score: 3.2, Last Audit: Dec 2024)
86
87Q4 2025:
88 - Breach Notification Process (Risk Score: 4.0, Last Audit: Mar 2024)
89 - Records of Processing Activities (Risk Score: 3.5, Last Audit: Sep 2024)
90
91Reserve/Contingency (50 hours):
92 - Ad hoc investigations, management requests, regulatory-triggered audits
93```
94
95## Audit Execution Phases
96
97### Phase 1: Planning and Scoping (1-2 Weeks)
98
99#### 1.1 Audit Charter Confirmation
100
101Confirm that the internal audit charter authorizes privacy audits and defines:
102
103- Audit authority and independence
104- Access to records, personnel, and systems
105- Reporting relationships
106- Confidentiality obligations of audit staff
107
108#### 1.2 Preliminary Research
109
110- Review applicable regulations and recent enforcement actions
111- Review prior audit reports and outstanding findings
112- Review recent privacy incidents, complaints, and DSAR metrics
113- Review organizational changes affecting the audit scope
114- Review regulatory guidance and supervisory authority publications
115
116#### 1.3 Scope Definition
117
118Document the audit scope including:
119
120| Scope Element | Description |
121|---------------|-------------|
122| Objective | What the audit intends to evaluate (e.g., adequacy and effectiveness of DSAR response controls) |
123| Period | The timeframe under examination (e.g., January 1 — June 30, 2025) |
124| Entities | Organizational units in scope |
125| Systems | IT systems and platforms in scope |
126| Regulations | Applicable legal requirements |
127| Standards | Applicable internal policies and external frameworks |
128| Exclusions | Explicitly out-of-scope areas with justification |
129
130#### 1.4 Audit Program Development
131
132Create the detailed audit program (test procedures) for each control objective:
133
134```
135Control Objective: DSARs are processed within regulatory timeframes
136 Test 1: Obtain DSAR tracking log for the audit period
137 Test 2: Select sample of [n] DSARs per sampling methodology
138 Test 3: For each sampled DSAR, verify:
139 a. Identity verification was completed before disclosure
140 b. Response was provided within 30 days (GDPR) or 45 days (CCPA)
141 c. Response contained all required information per Art. 15
142 d. Extension, if used, was communicated within initial deadline
143 e. Denial, if applicable, was justified and communicated with appeal rights
144 Test 4: Review DSAR metrics for trend analysis
145 Test 5: Interview DSAR coordinators on process adherence
146```
147
148#### 1.5 Engagement Letter
149
150Issue the engagement letter to the audit client (privacy operations team) containing:
151
152- Audit objective and scope
153- Audit period
154- Expected fieldwork dates
155- Information and access requirements
156- Key contacts
157- Preliminary meeting schedule
158
159### Phase 2: Fieldwork (2-4 Weeks)
160
161#### 2.1 Opening Meeting
162
163Conduct an opening meeting with the audit client to:
164
165- Confirm scope and timing
166- Identify key contacts for each area
167- Discuss logistics (room access, system access, document sharing)
168- Address any concerns or constraints
169
170#### 2.2 Evidence Gathering Techniques
171
172| Technique | Application | Example |
173|-----------|-------------|---------|
174| Document Review | Policies, procedures, records, reports | Review privacy policy against GDPR Art. 13-14 requirements |
175| Interview | Process understanding, control awareness | Interview DPO on DPIA review process |
176| Observation | Process walkthrough, system demonstration | Observe DSAR fulfillment from intake to response |
177| Data Analysis | Population analysis, trend identification, anomaly detection | Analyze DSAR response times across the full population |
178| Technical Testing | System configuration verification | Verify encryption-at-rest configuration on database |
179| Sampling | Representative testing of transactions | Select 30 DSARs from population of 450 for detailed testing |
180| Reperformance | Independent control execution | Submit test DSAR and verify correct handling |
181
182#### 2.3 Sampling Methodology
183
184Internal privacy audit sampling follows IIA Practice Guide "Audit Sampling":
185
186**Attribute Sampling** (for compliance testing):
187
188| Population Size | Expected Error Rate | 95% Confidence Sample |
189|----------------|--------------------|-----------------------|
190| 50-100 | 0% expected | 30 |
191| 101-500 | 0% expected | 40 |
192| 501-1000 | 0% expected | 50 |
193| 1000+ | 0% expected | 60 |
194| Any | 1-5% expected | Add 10-20 to above |
195
196**Judgmental Sampling** (risk-focused selection):
197
198- High-value transactions (DSARs involving sensitive data)
199- Edge cases (DSARs with extensions, partial denials, cross-border elements)
200- Time-based distribution (ensure coverage across the entire audit period)
201- New process implementation (overweight periods after process changes)
202
203#### 2.4 Working Paper Standards
204
205Every audit test must be documented in working papers containing:
206
207| Working Paper Element | Description |
208|----------------------|-------------|
209| Reference Number | Unique identifier linked to the audit program test step |
210| Objective | What the test is designed to evaluate |
211| Procedure | Detailed steps performed |
212| Population | Description and size of the population tested |
213| Sample | Size and selection methodology |
214| Results | Factual findings for each sample item |
215| Conclusion | Pass/Fail determination with reasoning |
216| Evidence | Attached or cross-referenced supporting documentation |
217| Preparer | Auditor name and date |
218| Reviewer | Reviewer name and date |
219
220### Phase 3: Finding Classification and Reporting (1-2 Weeks)
221
222#### 3.1 Finding Classification
223
224Each finding is classified by severity:
225
226| Severity | Criteria | Response Time |
227|----------|----------|---------------|
228| Critical | Systemic non-compliance with regulation; imminent risk of enforcement action, significant data breach, or harm to data subjects; complete control failure | Immediate: interim remediation within 5 business days; full remediation within 30 days |
229| High | Material non-compliance; control design deficiency or widespread operating failure; significant gap between policy and practice | Remediation plan within 10 business days; full remediation within 60 days |
230| Medium | Isolated non-compliance; control operating inconsistently; documentation gaps that could lead to material issues | Remediation within 90 days |
231| Low | Minor documentation gaps; process improvement opportunities; control enhancements that would strengthen compliance posture | Remediation within 180 days |
232| Advisory | Best practice recommendations; emerging risk observations; no current non-compliance | No required response; tracked for information |
233
234#### 3.2 Finding Structure
235
236Each finding is documented using the Condition-Criteria-Cause-Consequence-Recommendation format:
237
238```
239Finding ID: PA-2025-Q2-003
240Title: Incomplete identity verification for DSAR fulfillment
241Severity: High
242Status: Open
243
244Condition (What did we find?):
245 In 6 of 30 sampled DSARs (20%), the identity verification step was not
246 completed or documented prior to disclosing personal data to the requestor.
247 Affected requests: DSAR-2025-0147, DSAR-2025-0203, DSAR-2025-0289,
248 DSAR-2025-0312, DSAR-2025-0378, DSAR-2025-0401.
249
250Criteria (What should be happening?):
251 GDPR Art. 12(6) requires controllers to verify the identity of the data
252 subject making the request, particularly where the controller has reasonable
253 doubts. Sentinel Compliance Group Privacy Procedure PR-DSAR-001 Section 4.2
254 requires two-factor identity verification for all DSARs before any personal
255 data is disclosed.
256
257Cause (Why did it happen?):
258 The DSAR workflow system does not enforce a mandatory verification step before
259 allowing the coordinator to mark the request as "in progress." Three of the
260 six cases involved requests received via email rather than the self-service
261 portal, where the verification workflow is not automated.
262
263Consequence (What is the risk?):
264 Without proper identity verification, personal data may be disclosed to
265 unauthorized individuals, constituting a personal data breach under Art. 4(12)
266 GDPR. This could result in supervisory authority enforcement action, reputational
267 harm, and direct harm to data subjects. The ICO fined a UK company GBP 175,000
268 in 2023 for disclosing personal data in response to a fraudulent DSAR.
269
270Recommendation:
271 1. Implement a mandatory verification gate in the DSAR workflow system that
272 blocks progression until verification is completed and documented.
273 2. Extend automated verification to email-originated DSARs by redirecting
274 requestors to the self-service portal.
275 3. Retrain DSAR coordinators on verification requirements.
276
277Management Response: [To be completed by management]
278Remediation Owner: [To be assigned]
279Target Date: [To be set]
280```
281
282#### 3.3 Audit Report Structure
283
284```
285INTERNAL PRIVACY AUDIT REPORT
286Report Number: PA-2025-Q2
287Classification: Confidential
288
2891. Executive Summary
290 - Audit objective and scope
291 - Overall rating (Satisfactory / Needs Improvement / Unsatisfactory)
292 - Summary of findings by severity
293 - Key themes and systemic issues
294
2952. Audit Scope and Approach
296 - Detailed scope description
297 - Regulations and standards tested against
298 - Methodology (sampling, testing approach)
299 - Period covered
300 - Limitations and constraints
301
3023. Findings and Recommendations
303 - Critical findings (if any)
304 - High findings
305 - Medium findings
306 - Low findings
307 - Advisory observations
308
3094. Management Action Plans
310 - Agreed remediation actions per finding
311 - Responsible owners
312 - Target completion dates
313
3145. Prior Audit Follow-Up
315 - Status of findings from prior audits
316 - Closed findings with verification evidence
317 - Overdue findings with escalation status
318
3196. Appendices
320 - Detailed test results
321 - Population and sample details
322 - Documents reviewed
323 - Personnel interviewed
324```
325
326#### 3.4 Overall Audit Rating
327
328| Rating | Criteria |
329|--------|----------|
330| Satisfactory | No critical or high findings; medium and low findings do not indicate systemic issues; controls are generally effective |
331| Needs Improvement | One or more high findings OR multiple medium findings indicating a pattern; controls are partially effective but require strengthening |
332| Unsatisfactory | One or more critical findings OR multiple high findings; fundamental control failures exist; immediate management attention required |
333
334### Phase 4: Remediation Tracking (Ongoing)
335
336#### 4.1 Remediation Lifecycle
337
338```
339Finding Issued → Management Response (10 business days) → Remediation In Progress
340→ Owner Reports Completion → Audit Verification Testing → Finding Closed OR
341→ Reopened with Revised Plan
342```
343
344#### 4.2 Tracking Dashboard
345
346| Metric | Measurement |
347|--------|-------------|
348| Open Findings by Severity | Count of open findings per critical/high/medium/low |
349| Overdue Findings | Count and percentage of findings past target date |
350| Average Time to Remediate | Mean days from finding issuance to verified closure |
351| Remediation Effectiveness | Percentage of findings closed on first attempt (not reopened) |
352| Recurrence Rate | Percentage of findings that reappear in subsequent audits |
353
354#### 4.3 Escalation Protocol
355
356| Condition | Escalation Level |
357|-----------|------------------|
358| Critical finding not addressed within 5 business days | Chief Privacy Officer and CISO |
359| High finding overdue by 30+ days | Chief Audit Executive to Audit Committee |
360| Medium finding overdue by 60+ days | Chief Audit Executive to management |
361| Pattern of repeated findings in same area | Chief Audit Executive to Audit Committee |
362| Management refuses to remediate | Chief Audit Executive to Audit Committee and Board |
363
364### Phase 5: Management Reporting (Quarterly)
365
366#### 5.1 Quarterly Privacy Audit Report to Audit Committee
367
368- Summary of audits completed in the quarter
369- Summary of findings by severity and theme
370- Remediation progress dashboard
371- Emerging privacy risks identified
372- Annual audit plan status and any proposed adjustments
373- Resource utilization and any capacity constraints
374
375#### 5.2 Annual Privacy Audit Summary
376
377- All audits completed during the year
378- Trend analysis of findings across the year
379- Assessment of the organization's overall privacy posture
380- Comparison to prior year
381- Recommendations for the following year's audit plan
382- Lessons learned and methodology improvements
383
384## Sentinel Compliance Group Internal Privacy Audit Program
385
386Sentinel Compliance Group operates an internal privacy audit program with the following characteristics:
387
388- **Team**: Two dedicated privacy auditors plus one co-sourced external privacy audit specialist
389- **Annual Audit Hours**: 1,200 hours allocated to privacy audits
390- **Audits Per Year**: 8-10 privacy audits plus continuous monitoring activities
391- **Reporting Line**: Chief Audit Executive reports to the Audit Committee; privacy audit results shared with the DPO
392- **Tools**: AuditBoard for working papers and finding management; ServiceNow for remediation tracking
393- **2024 Results**: 9 audits completed, 47 findings issued (2 critical, 8 high, 22 medium, 15 low), 89% remediation rate within target dates, overall privacy posture rated "Needs Improvement" trending toward "Satisfactory"