Internal Privacy Audit Program
Overview
An internal privacy audit program provides systematic, independent assurance that an organization's privacy practices conform to applicable data protection regulations, internal policies, contractual obligations, and recognized frameworks. Unlike external audits (SOC 2, ISO 27701 certification), internal privacy audits are conducted by or on behalf of the organization itself, giving management direct visibility into compliance gaps before they become regulatory findings or breaches.
The internal privacy audit function operates under the IIA (Institute of Internal Auditors) International Standards for the Professional Practice of Internal Auditing and adapts these standards to the privacy domain. At Sentinel Compliance Group, the internal privacy audit program reports to the Audit Committee of the Board of Directors, maintaining independence from the privacy operations function it audits.
Audit Universe Definition
The privacy audit universe represents the complete set of auditable entities, processes, and systems relevant to privacy compliance. It forms the basis for risk-based audit planning.
Privacy Audit Universe Categories
| Category |
Auditable Areas |
Example Entities |
| Regulatory Compliance |
GDPR, CCPA/CPRA, LGPD, PIPA, sector-specific laws |
EU processing operations, California consumer data handling, Brazilian customer data |
| Data Lifecycle |
Collection, processing, storage, sharing, retention, deletion |
Web forms, CRM system, data warehouse, third-party APIs, backup systems |
| Data Subject Rights |
Access, rectification, erasure, portability, restriction, objection |
DSAR intake process, identity verification, response workflow, automated systems |
| Third-Party Management |
Processors, sub-processors, joint controllers, data sharing |
Cloud hosting, analytics vendors, marketing platforms, payment processors |
| Privacy Governance |
Policies, training, DPO function, privacy committee, DPIA process |
Privacy policy management, training program, DPO independence, DPIA register |
| Technical Controls |
Encryption, access controls, pseudonymization, logging, deletion |
Database encryption, IAM configuration, log management, automated purge jobs |
| Breach Management |
Detection, assessment, notification, documentation, remediation |
SIEM configuration, breach assessment process, DPA notification, root cause analysis |
| Cross-Border Transfers |
Transfer mechanisms, TIAs, supplementary measures |
SCCs, BCRs, adequacy decisions, data localization controls |
| Consent Management |
Collection, recording, withdrawal, preference management |
Consent platforms, cookie banners, preference centers, consent databases |
| Records of Processing |
RoPA completeness, accuracy, maintenance |
Controller register, processor register, update workflow |
Risk-Based Prioritization
Each auditable area is scored on a risk matrix:
| Risk Factor |
Weight |
Scoring (1-5) |
| Regulatory exposure |
25% |
1 = No regulation, 5 = Multiple strict regulations with active enforcement |
| Volume of personal data |
20% |
1 = Minimal PII, 5 = Large-scale special category data |
| Prior audit findings |
15% |
1 = No findings, 5 = Unresolved critical findings |
| Organizational change |
15% |
1 = Stable, 5 = Major system/process changes |
| Third-party dependency |
10% |
1 = No third parties, 5 = Critical third-party processing |
| Complaint/incident history |
10% |
1 = No incidents, 5 = Multiple privacy incidents |
| Time since last audit |
5% |
1 = Audited this quarter, 5 = Never audited or >2 years |
Risk Score Calculation: Weighted sum of all factors (maximum 5.0)
| Risk Score |
Audit Frequency |
| 4.0 — 5.0 |
Every 6 months |
| 3.0 — 3.9 |
Annual |
| 2.0 — 2.9 |
Every 18 months |
| 1.0 — 1.9 |
Every 24 months or as resources permit |
Annual Audit Plan
Plan Development Process
- Update Audit Universe (Q4 of preceding year): Review the audit universe for new systems, regulations, processing activities, and organizational changes
- Conduct Risk Assessment (Q4): Score each auditable area using the risk matrix above
- Allocate Resources (Q4): Determine available audit hours based on team size and skill sets
- Draft Annual Plan (Q4): Schedule audits by quarter, balancing risk priority with resource availability and organizational calendar constraints
- Management Approval (Q4): Present the annual audit plan to the Audit Committee for approval
- Quarterly Review (each quarter): Adjust the plan based on emerging risks, regulatory changes, or management requests
Annual Plan Template
Sentinel Compliance Group — Privacy Audit Annual Plan 2025
Approved By: Audit Committee, December 15, 2024
Plan Owner: Chief Audit Executive
Q1 2025:
- DSAR Response Process (Risk Score: 4.3, Last Audit: Jun 2024)
- Cookie Consent Management (Risk Score: 3.8, Last Audit: Mar 2024)
Q2 2025:
- Third-Party Processor Management (Risk Score: 4.5, Last Audit: Dec 2023)
- Cross-Border Data Transfers (Risk Score: 4.1, Last Audit: Sep 2024)
Q3 2025:
- Data Retention and Deletion (Risk Score: 3.9, Last Audit: Jun 2024)
- Privacy Training Effectiveness (Risk Score: 3.2, Last Audit: Dec 2024)
Q4 2025:
- Breach Notification Process (Risk Score: 4.0, Last Audit: Mar 2024)
- Records of Processing Activities (Risk Score: 3.5, Last Audit: Sep 2024)
Reserve/Contingency (50 hours):
- Ad hoc investigations, management requests, regulatory-triggered audits
Audit Execution Phases
Phase 1: Planning and Scoping (1-2 Weeks)
1.1 Audit Charter Confirmation
Confirm that the internal audit charter authorizes privacy audits and defines:
- Audit authority and independence
- Access to records, personnel, and systems
- Reporting relationships
- Confidentiality obligations of audit staff
1.2 Preliminary Research
- Review applicable regulations and recent enforcement actions
- Review prior audit reports and outstanding findings
- Review recent privacy incidents, complaints, and DSAR metrics
- Review organizational changes affecting the audit scope
- Review regulatory guidance and supervisory authority publications
1.3 Scope Definition
Document the audit scope including:
| Scope Element |
Description |
| Objective |
What the audit intends to evaluate (e.g., adequacy and effectiveness of DSAR response controls) |
| Period |
The timeframe under examination (e.g., January 1 — June 30, 2025) |
| Entities |
Organizational units in scope |
| Systems |
IT systems and platforms in scope |
| Regulations |
Applicable legal requirements |
| Standards |
Applicable internal policies and external frameworks |
| Exclusions |
Explicitly out-of-scope areas with justification |
1.4 Audit Program Development
Create the detailed audit program (test procedures) for each control objective:
Control Objective: DSARs are processed within regulatory timeframes
Test 1: Obtain DSAR tracking log for the audit period
Test 2: Select sample of [n] DSARs per sampling methodology
Test 3: For each sampled DSAR, verify:
a. Identity verification was completed before disclosure
b. Response was provided within 30 days (GDPR) or 45 days (CCPA)
c. Response contained all required information per Art. 15
d. Extension, if used, was communicated within initial deadline
e. Denial, if applicable, was justified and communicated with appeal rights
Test 4: Review DSAR metrics for trend analysis
Test 5: Interview DSAR coordinators on process adherence
1.5 Engagement Letter
Issue the engagement letter to the audit client (privacy operations team) containing:
- Audit objective and scope
- Audit period
- Expected fieldwork dates
- Information and access requirements
- Key contacts
- Preliminary meeting schedule
Phase 2: Fieldwork (2-4 Weeks)
2.1 Opening Meeting
Conduct an opening meeting with the audit client to:
- Confirm scope and timing
- Identify key contacts for each area
- Discuss logistics (room access, system access, document sharing)
- Address any concerns or constraints
2.2 Evidence Gathering Techniques
| Technique |
Application |
Example |
| Document Review |
Policies, procedures, records, reports |
Review privacy policy against GDPR Art. 13-14 requirements |
| Interview |
Process understanding, control awareness |
Interview DPO on DPIA review process |
| Observation |
Process walkthrough, system demonstration |
Observe DSAR fulfillment from intake to response |
| Data Analysis |
Population analysis, trend identification, anomaly detection |
Analyze DSAR response times across the full population |
| Technical Testing |
System configuration verification |
Verify encryption-at-rest configuration on database |
| Sampling |
Representative testing of transactions |
Select 30 DSARs from population of 450 for detailed testing |
| Reperformance |
Independent control execution |
Submit test DSAR and verify correct handling |
2.3 Sampling Methodology
Internal privacy audit sampling follows IIA Practice Guide "Audit Sampling":
Attribute Sampling (for compliance testing):
| Population Size |
Expected Error Rate |
95% Confidence Sample |
| 50-100 |
0% expected |
30 |
| 101-500 |
0% expected |
40 |
| 501-1000 |
0% expected |
50 |
| 1000+ |
0% expected |
60 |
| Any |
1-5% expected |
Add 10-20 to above |
Judgmental Sampling (risk-focused selection):
- High-value transactions (DSARs involving sensitive data)
- Edge cases (DSARs with extensions, partial denials, cross-border elements)
- Time-based distribution (ensure coverage across the entire audit period)
- New process implementation (overweight periods after process changes)
2.4 Working Paper Standards
Every audit test must be documented in working papers containing:
| Working Paper Element |
Description |
| Reference Number |
Unique identifier linked to the audit program test step |
| Objective |
What the test is designed to evaluate |
| Procedure |
Detailed steps performed |
| Population |
Description and size of the population tested |
| Sample |
Size and selection methodology |
| Results |
Factual findings for each sample item |
| Conclusion |
Pass/Fail determination with reasoning |
| Evidence |
Attached or cross-referenced supporting documentation |
| Preparer |
Auditor name and date |
| Reviewer |
Reviewer name and date |
Phase 3: Finding Classification and Reporting (1-2 Weeks)
3.1 Finding Classification
Each finding is classified by severity:
| Severity |
Criteria |
Response Time |
| Critical |
Systemic non-compliance with regulation; imminent risk of enforcement action, significant data breach, or harm to data subjects; complete control failure |
Immediate: interim remediation within 5 business days; full remediation within 30 days |
| High |
Material non-compliance; control design deficiency or widespread operating failure; significant gap between policy and practice |
Remediation plan within 10 business days; full remediation within 60 days |
| Medium |
Isolated non-compliance; control operating inconsistently; documentation gaps that could lead to material issues |
Remediation within 90 days |
| Low |
Minor documentation gaps; process improvement opportunities; control enhancements that would strengthen compliance posture |
Remediation within 180 days |
| Advisory |
Best practice recommendations; emerging risk observations; no current non-compliance |
No required response; tracked for information |
3.2 Finding Structure
Each finding is documented using the Condition-Criteria-Cause-Consequence-Recommendation format:
Finding ID: PA-2025-Q2-003
Title: Incomplete identity verification for DSAR fulfillment
Severity: High
Status: Open
Condition (What did we find?):
In 6 of 30 sampled DSARs (20%), the identity verification step was not
completed or documented prior to disclosing personal data to the requestor.
Affected requests: DSAR-2025-0147, DSAR-2025-0203, DSAR-2025-0289,
DSAR-2025-0312, DSAR-2025-0378, DSAR-2025-0401.
Criteria (What should be happening?):
GDPR Art. 12(6) requires controllers to verify the identity of the data
subject making the request, particularly where the controller has reasonable
doubts. Sentinel Compliance Group Privacy Procedure PR-DSAR-001 Section 4.2
requires two-factor identity verification for all DSARs before any personal
data is disclosed.
Cause (Why did it happen?):
The DSAR workflow system does not enforce a mandatory verification step before
allowing the coordinator to mark the request as "in progress." Three of the
six cases involved requests received via email rather than the self-service
portal, where the verification workflow is not automated.
Consequence (What is the risk?):
Without proper identity verification, personal data may be disclosed to
unauthorized individuals, constituting a personal data breach under Art. 4(12)
GDPR. This could result in supervisory authority enforcement action, reputational
harm, and direct harm to data subjects. The ICO fined a UK company GBP 175,000
in 2023 for disclosing personal data in response to a fraudulent DSAR.
Recommendation:
1. Implement a mandatory verification gate in the DSAR workflow system that
blocks progression until verification is completed and documented.
2. Extend automated verification to email-originated DSARs by redirecting
requestors to the self-service portal.
3. Retrain DSAR coordinators on verification requirements.
Management Response: [To be completed by management]
Remediation Owner: [To be assigned]
Target Date: [To be set]
3.3 Audit Report Structure
INTERNAL PRIVACY AUDIT REPORT
Report Number: PA-2025-Q2
Classification: Confidential
1. Executive Summary
- Audit objective and scope
- Overall rating (Satisfactory / Needs Improvement / Unsatisfactory)
- Summary of findings by severity
- Key themes and systemic issues
2. Audit Scope and Approach
- Detailed scope description
- Regulations and standards tested against
- Methodology (sampling, testing approach)
- Period covered
- Limitations and constraints
3. Findings and Recommendations
- Critical findings (if any)
- High findings
- Medium findings
- Low findings
- Advisory observations
4. Management Action Plans
- Agreed remediation actions per finding
- Responsible owners
- Target completion dates
5. Prior Audit Follow-Up
- Status of findings from prior audits
- Closed findings with verification evidence
- Overdue findings with escalation status
6. Appendices
- Detailed test results
- Population and sample details
- Documents reviewed
- Personnel interviewed
3.4 Overall Audit Rating
| Rating |
Criteria |
| Satisfactory |
No critical or high findings; medium and low findings do not indicate systemic issues; controls are generally effective |
| Needs Improvement |
One or more high findings OR multiple medium findings indicating a pattern; controls are partially effective but require strengthening |
| Unsatisfactory |
One or more critical findings OR multiple high findings; fundamental control failures exist; immediate management attention required |
Phase 4: Remediation Tracking (Ongoing)
4.1 Remediation Lifecycle
Finding Issued → Management Response (10 business days) → Remediation In Progress
→ Owner Reports Completion → Audit Verification Testing → Finding Closed OR
→ Reopened with Revised Plan
4.2 Tracking Dashboard
| Metric |
Measurement |
| Open Findings by Severity |
Count of open findings per critical/high/medium/low |
| Overdue Findings |
Count and percentage of findings past target date |
| Average Time to Remediate |
Mean days from finding issuance to verified closure |
| Remediation Effectiveness |
Percentage of findings closed on first attempt (not reopened) |
| Recurrence Rate |
Percentage of findings that reappear in subsequent audits |
4.3 Escalation Protocol
| Condition |
Escalation Level |
| Critical finding not addressed within 5 business days |
Chief Privacy Officer and CISO |
| High finding overdue by 30+ days |
Chief Audit Executive to Audit Committee |
| Medium finding overdue by 60+ days |
Chief Audit Executive to management |
| Pattern of repeated findings in same area |
Chief Audit Executive to Audit Committee |
| Management refuses to remediate |
Chief Audit Executive to Audit Committee and Board |
Phase 5: Management Reporting (Quarterly)
5.1 Quarterly Privacy Audit Report to Audit Committee
- Summary of audits completed in the quarter
- Summary of findings by severity and theme
- Remediation progress dashboard
- Emerging privacy risks identified
- Annual audit plan status and any proposed adjustments
- Resource utilization and any capacity constraints
5.2 Annual Privacy Audit Summary
- All audits completed during the year
- Trend analysis of findings across the year
- Assessment of the organization's overall privacy posture
- Comparison to prior year
- Recommendations for the following year's audit plan
- Lessons learned and methodology improvements
Sentinel Compliance Group Internal Privacy Audit Program
Sentinel Compliance Group operates an internal privacy audit program with the following characteristics:
- Team: Two dedicated privacy auditors plus one co-sourced external privacy audit specialist
- Annual Audit Hours: 1,200 hours allocated to privacy audits
- Audits Per Year: 8-10 privacy audits plus continuous monitoring activities
- Reporting Line: Chief Audit Executive reports to the Audit Committee; privacy audit results shared with the DPO
- Tools: AuditBoard for working papers and finding management; ServiceNow for remediation tracking
- 2024 Results: 9 audits completed, 47 findings issued (2 critical, 8 high, 22 medium, 15 low), 89% remediation rate within target dates, overall privacy posture rated "Needs Improvement" trending toward "Satisfactory"
1---2name: internal-privacy-audit3description: Guides internal privacy audit program design and execution including risk-based audit planning, scope definition, fieldwork procedures, finding classification, evidence gathering, remediation tracking, and management reporting. Covers audit universe definition, annual audit plan, working papers, and closure verification. Keywords: internal audit, privacy audit, fieldwork, remediation, findings, audit plan.4license: Apache-2.05---67# Internal Privacy Audit Program89## Overview1011An internal privacy audit program provides systematic, independent assurance that an organization's privacy practices conform to applicable data protection regulations, internal policies, contractual obligations, and recognized frameworks. Unlike external audits (SOC 2, ISO 27701 certification), internal privacy audits are conducted by or on behalf of the organization itself, giving management direct visibility into compliance gaps before they become regulatory findings or breaches.1213The internal privacy audit function operates under the IIA (Institute of Internal Auditors) International Standards for the Professional Practice of Internal Auditing and adapts these standards to the privacy domain. At Sentinel Compliance Group, the internal privacy audit program reports to the Audit Committee of the Board of Directors, maintaining independence from the privacy operations function it audits.1415## Audit Universe Definition1617The privacy audit universe represents the complete set of auditable entities, processes, and systems relevant to privacy compliance. It forms the basis for risk-based audit planning.1819### Privacy Audit Universe Categories2021| Category | Auditable Areas | Example Entities |22|----------|----------------|------------------|23| Regulatory Compliance | GDPR, CCPA/CPRA, LGPD, PIPA, sector-specific laws | EU processing operations, California consumer data handling, Brazilian customer data |24| Data Lifecycle | Collection, processing, storage, sharing, retention, deletion | Web forms, CRM system, data warehouse, third-party APIs, backup systems |25| Data Subject Rights | Access, rectification, erasure, portability, restriction, objection | DSAR intake process, identity verification, response workflow, automated systems |26| Third-Party Management | Processors, sub-processors, joint controllers, data sharing | Cloud hosting, analytics vendors, marketing platforms, payment processors |27| Privacy Governance | Policies, training, DPO function, privacy committee, DPIA process | Privacy policy management, training program, DPO independence, DPIA register |28| Technical Controls | Encryption, access controls, pseudonymization, logging, deletion | Database encryption, IAM configuration, log management, automated purge jobs |29| Breach Management | Detection, assessment, notification, documentation, remediation | SIEM configuration, breach assessment process, DPA notification, root cause analysis |30| Cross-Border Transfers | Transfer mechanisms, TIAs, supplementary measures | SCCs, BCRs, adequacy decisions, data localization controls |31| Consent Management | Collection, recording, withdrawal, preference management | Consent platforms, cookie banners, preference centers, consent databases |32| Records of Processing | RoPA completeness, accuracy, maintenance | Controller register, processor register, update workflow |3334### Risk-Based Prioritization3536Each auditable area is scored on a risk matrix:3738| Risk Factor | Weight | Scoring (1-5) |39|-------------|--------|----------------|40| Regulatory exposure | 25% | 1 = No regulation, 5 = Multiple strict regulations with active enforcement |41| Volume of personal data | 20% | 1 = Minimal PII, 5 = Large-scale special category data |42| Prior audit findings | 15% | 1 = No findings, 5 = Unresolved critical findings |43| Organizational change | 15% | 1 = Stable, 5 = Major system/process changes |44| Third-party dependency | 10% | 1 = No third parties, 5 = Critical third-party processing |45| Complaint/incident history | 10% | 1 = No incidents, 5 = Multiple privacy incidents |46| Time since last audit | 5% | 1 = Audited this quarter, 5 = Never audited or >2 years |4748**Risk Score Calculation**: Weighted sum of all factors (maximum 5.0)4950| Risk Score | Audit Frequency |51|-----------|-----------------|52| 4.0 — 5.0 | Every 6 months |53| 3.0 — 3.9 | Annual |54| 2.0 — 2.9 | Every 18 months |55| 1.0 — 1.9 | Every 24 months or as resources permit |5657## Annual Audit Plan5859### Plan Development Process60611. **Update Audit Universe** (Q4 of preceding year): Review the audit universe for new systems, regulations, processing activities, and organizational changes622. **Conduct Risk Assessment** (Q4): Score each auditable area using the risk matrix above633. **Allocate Resources** (Q4): Determine available audit hours based on team size and skill sets644. **Draft Annual Plan** (Q4): Schedule audits by quarter, balancing risk priority with resource availability and organizational calendar constraints655. **Management Approval** (Q4): Present the annual audit plan to the Audit Committee for approval666. **Quarterly Review** (each quarter): Adjust the plan based on emerging risks, regulatory changes, or management requests6768### Annual Plan Template6970```71Sentinel Compliance Group — Privacy Audit Annual Plan 20257273Approved By: Audit Committee, December 15, 202474Plan Owner: Chief Audit Executive7576Q1 2025:77 - DSAR Response Process (Risk Score: 4.3, Last Audit: Jun 2024)78 - Cookie Consent Management (Risk Score: 3.8, Last Audit: Mar 2024)7980Q2 2025:81 - Third-Party Processor Management (Risk Score: 4.5, Last Audit: Dec 2023)82 - Cross-Border Data Transfers (Risk Score: 4.1, Last Audit: Sep 2024)8384Q3 2025:85 - Data Retention and Deletion (Risk Score: 3.9, Last Audit: Jun 2024)86 - Privacy Training Effectiveness (Risk Score: 3.2, Last Audit: Dec 2024)8788Q4 2025:89 - Breach Notification Process (Risk Score: 4.0, Last Audit: Mar 2024)90 - Records of Processing Activities (Risk Score: 3.5, Last Audit: Sep 2024)9192Reserve/Contingency (50 hours):93 - Ad hoc investigations, management requests, regulatory-triggered audits94```9596## Audit Execution Phases9798### Phase 1: Planning and Scoping (1-2 Weeks)99100#### 1.1 Audit Charter Confirmation101102Confirm that the internal audit charter authorizes privacy audits and defines:103104- Audit authority and independence105- Access to records, personnel, and systems106- Reporting relationships107- Confidentiality obligations of audit staff108109#### 1.2 Preliminary Research110111- Review applicable regulations and recent enforcement actions112- Review prior audit reports and outstanding findings113- Review recent privacy incidents, complaints, and DSAR metrics114- Review organizational changes affecting the audit scope115- Review regulatory guidance and supervisory authority publications116117#### 1.3 Scope Definition118119Document the audit scope including:120121| Scope Element | Description |122|---------------|-------------|123| Objective | What the audit intends to evaluate (e.g., adequacy and effectiveness of DSAR response controls) |124| Period | The timeframe under examination (e.g., January 1 — June 30, 2025) |125| Entities | Organizational units in scope |126| Systems | IT systems and platforms in scope |127| Regulations | Applicable legal requirements |128| Standards | Applicable internal policies and external frameworks |129| Exclusions | Explicitly out-of-scope areas with justification |130131#### 1.4 Audit Program Development132133Create the detailed audit program (test procedures) for each control objective:134135```136Control Objective: DSARs are processed within regulatory timeframes137 Test 1: Obtain DSAR tracking log for the audit period138 Test 2: Select sample of [n] DSARs per sampling methodology139 Test 3: For each sampled DSAR, verify:140 a. Identity verification was completed before disclosure141 b. Response was provided within 30 days (GDPR) or 45 days (CCPA)142 c. Response contained all required information per Art. 15143 d. Extension, if used, was communicated within initial deadline144 e. Denial, if applicable, was justified and communicated with appeal rights145 Test 4: Review DSAR metrics for trend analysis146 Test 5: Interview DSAR coordinators on process adherence147```148149#### 1.5 Engagement Letter150151Issue the engagement letter to the audit client (privacy operations team) containing:152153- Audit objective and scope154- Audit period155- Expected fieldwork dates156- Information and access requirements157- Key contacts158- Preliminary meeting schedule159160### Phase 2: Fieldwork (2-4 Weeks)161162#### 2.1 Opening Meeting163164Conduct an opening meeting with the audit client to:165166- Confirm scope and timing167- Identify key contacts for each area168- Discuss logistics (room access, system access, document sharing)169- Address any concerns or constraints170171#### 2.2 Evidence Gathering Techniques172173| Technique | Application | Example |174|-----------|-------------|---------|175| Document Review | Policies, procedures, records, reports | Review privacy policy against GDPR Art. 13-14 requirements |176| Interview | Process understanding, control awareness | Interview DPO on DPIA review process |177| Observation | Process walkthrough, system demonstration | Observe DSAR fulfillment from intake to response |178| Data Analysis | Population analysis, trend identification, anomaly detection | Analyze DSAR response times across the full population |179| Technical Testing | System configuration verification | Verify encryption-at-rest configuration on database |180| Sampling | Representative testing of transactions | Select 30 DSARs from population of 450 for detailed testing |181| Reperformance | Independent control execution | Submit test DSAR and verify correct handling |182183#### 2.3 Sampling Methodology184185Internal privacy audit sampling follows IIA Practice Guide "Audit Sampling":186187**Attribute Sampling** (for compliance testing):188189| Population Size | Expected Error Rate | 95% Confidence Sample |190|----------------|--------------------|-----------------------|191| 50-100 | 0% expected | 30 |192| 101-500 | 0% expected | 40 |193| 501-1000 | 0% expected | 50 |194| 1000+ | 0% expected | 60 |195| Any | 1-5% expected | Add 10-20 to above |196197**Judgmental Sampling** (risk-focused selection):198199- High-value transactions (DSARs involving sensitive data)200- Edge cases (DSARs with extensions, partial denials, cross-border elements)201- Time-based distribution (ensure coverage across the entire audit period)202- New process implementation (overweight periods after process changes)203204#### 2.4 Working Paper Standards205206Every audit test must be documented in working papers containing:207208| Working Paper Element | Description |209|----------------------|-------------|210| Reference Number | Unique identifier linked to the audit program test step |211| Objective | What the test is designed to evaluate |212| Procedure | Detailed steps performed |213| Population | Description and size of the population tested |214| Sample | Size and selection methodology |215| Results | Factual findings for each sample item |216| Conclusion | Pass/Fail determination with reasoning |217| Evidence | Attached or cross-referenced supporting documentation |218| Preparer | Auditor name and date |219| Reviewer | Reviewer name and date |220221### Phase 3: Finding Classification and Reporting (1-2 Weeks)222223#### 3.1 Finding Classification224225Each finding is classified by severity:226227| Severity | Criteria | Response Time |228|----------|----------|---------------|229| Critical | Systemic non-compliance with regulation; imminent risk of enforcement action, significant data breach, or harm to data subjects; complete control failure | Immediate: interim remediation within 5 business days; full remediation within 30 days |230| High | Material non-compliance; control design deficiency or widespread operating failure; significant gap between policy and practice | Remediation plan within 10 business days; full remediation within 60 days |231| Medium | Isolated non-compliance; control operating inconsistently; documentation gaps that could lead to material issues | Remediation within 90 days |232| Low | Minor documentation gaps; process improvement opportunities; control enhancements that would strengthen compliance posture | Remediation within 180 days |233| Advisory | Best practice recommendations; emerging risk observations; no current non-compliance | No required response; tracked for information |234235#### 3.2 Finding Structure236237Each finding is documented using the Condition-Criteria-Cause-Consequence-Recommendation format:238239```240Finding ID: PA-2025-Q2-003241Title: Incomplete identity verification for DSAR fulfillment242Severity: High243Status: Open244245Condition (What did we find?):246 In 6 of 30 sampled DSARs (20%), the identity verification step was not247 completed or documented prior to disclosing personal data to the requestor.248 Affected requests: DSAR-2025-0147, DSAR-2025-0203, DSAR-2025-0289,249 DSAR-2025-0312, DSAR-2025-0378, DSAR-2025-0401.250251Criteria (What should be happening?):252 GDPR Art. 12(6) requires controllers to verify the identity of the data253 subject making the request, particularly where the controller has reasonable254 doubts. Sentinel Compliance Group Privacy Procedure PR-DSAR-001 Section 4.2255 requires two-factor identity verification for all DSARs before any personal256 data is disclosed.257258Cause (Why did it happen?):259 The DSAR workflow system does not enforce a mandatory verification step before260 allowing the coordinator to mark the request as "in progress." Three of the261 six cases involved requests received via email rather than the self-service262 portal, where the verification workflow is not automated.263264Consequence (What is the risk?):265 Without proper identity verification, personal data may be disclosed to266 unauthorized individuals, constituting a personal data breach under Art. 4(12)267 GDPR. This could result in supervisory authority enforcement action, reputational268 harm, and direct harm to data subjects. The ICO fined a UK company GBP 175,000269 in 2023 for disclosing personal data in response to a fraudulent DSAR.270271Recommendation:272 1. Implement a mandatory verification gate in the DSAR workflow system that273 blocks progression until verification is completed and documented.274 2. Extend automated verification to email-originated DSARs by redirecting275 requestors to the self-service portal.276 3. Retrain DSAR coordinators on verification requirements.277278Management Response: [To be completed by management]279Remediation Owner: [To be assigned]280Target Date: [To be set]281```282283#### 3.3 Audit Report Structure284285```286INTERNAL PRIVACY AUDIT REPORT287Report Number: PA-2025-Q2288Classification: Confidential2892901. Executive Summary291 - Audit objective and scope292 - Overall rating (Satisfactory / Needs Improvement / Unsatisfactory)293 - Summary of findings by severity294 - Key themes and systemic issues2952962. Audit Scope and Approach297 - Detailed scope description298 - Regulations and standards tested against299 - Methodology (sampling, testing approach)300 - Period covered301 - Limitations and constraints3023033. Findings and Recommendations304 - Critical findings (if any)305 - High findings306 - Medium findings307 - Low findings308 - Advisory observations3093104. Management Action Plans311 - Agreed remediation actions per finding312 - Responsible owners313 - Target completion dates3143155. Prior Audit Follow-Up316 - Status of findings from prior audits317 - Closed findings with verification evidence318 - Overdue findings with escalation status3193206. Appendices321 - Detailed test results322 - Population and sample details323 - Documents reviewed324 - Personnel interviewed325```326327#### 3.4 Overall Audit Rating328329| Rating | Criteria |330|--------|----------|331| Satisfactory | No critical or high findings; medium and low findings do not indicate systemic issues; controls are generally effective |332| Needs Improvement | One or more high findings OR multiple medium findings indicating a pattern; controls are partially effective but require strengthening |333| Unsatisfactory | One or more critical findings OR multiple high findings; fundamental control failures exist; immediate management attention required |334335### Phase 4: Remediation Tracking (Ongoing)336337#### 4.1 Remediation Lifecycle338339```340Finding Issued → Management Response (10 business days) → Remediation In Progress341→ Owner Reports Completion → Audit Verification Testing → Finding Closed OR342→ Reopened with Revised Plan343```344345#### 4.2 Tracking Dashboard346347| Metric | Measurement |348|--------|-------------|349| Open Findings by Severity | Count of open findings per critical/high/medium/low |350| Overdue Findings | Count and percentage of findings past target date |351| Average Time to Remediate | Mean days from finding issuance to verified closure |352| Remediation Effectiveness | Percentage of findings closed on first attempt (not reopened) |353| Recurrence Rate | Percentage of findings that reappear in subsequent audits |354355#### 4.3 Escalation Protocol356357| Condition | Escalation Level |358|-----------|------------------|359| Critical finding not addressed within 5 business days | Chief Privacy Officer and CISO |360| High finding overdue by 30+ days | Chief Audit Executive to Audit Committee |361| Medium finding overdue by 60+ days | Chief Audit Executive to management |362| Pattern of repeated findings in same area | Chief Audit Executive to Audit Committee |363| Management refuses to remediate | Chief Audit Executive to Audit Committee and Board |364365### Phase 5: Management Reporting (Quarterly)366367#### 5.1 Quarterly Privacy Audit Report to Audit Committee368369- Summary of audits completed in the quarter370- Summary of findings by severity and theme371- Remediation progress dashboard372- Emerging privacy risks identified373- Annual audit plan status and any proposed adjustments374- Resource utilization and any capacity constraints375376#### 5.2 Annual Privacy Audit Summary377378- All audits completed during the year379- Trend analysis of findings across the year380- Assessment of the organization's overall privacy posture381- Comparison to prior year382- Recommendations for the following year's audit plan383- Lessons learned and methodology improvements384385## Sentinel Compliance Group Internal Privacy Audit Program386387Sentinel Compliance Group operates an internal privacy audit program with the following characteristics:388389- **Team**: Two dedicated privacy auditors plus one co-sourced external privacy audit specialist390- **Annual Audit Hours**: 1,200 hours allocated to privacy audits391- **Audits Per Year**: 8-10 privacy audits plus continuous monitoring activities392- **Reporting Line**: Chief Audit Executive reports to the Audit Committee; privacy audit results shared with the DPO393- **Tools**: AuditBoard for working papers and finding management; ServiceNow for remediation tracking394- **2024 Results**: 9 audits completed, 47 findings issued (2 critical, 8 high, 22 medium, 15 low), 89% remediation rate within target dates, overall privacy posture rated "Needs Improvement" trending toward "Satisfactory"