AICPA Privacy Management Framework (PMF)
Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Access
Data subjects can access, review, and request corrections to their personal information held by the organisation.
- Access-request handling with identity authentication
- Provision of PI in understandable form
- No mechanism for data subjects to access their PI
Organisation has procedures for authenticating data subjects and responding to access requests in a timely manner.
- Correction/amendment process
- Notification of corrections to third parties
- Correction requests not actioned
Agreement, Notice, and Communication
Organisation provides clear and conspicuous notice about its privacy practices to data subjects.
- Clear, conspicuous privacy notice
- Notice content covering required items
- No privacy notice provided to data subjects
Organisation specifies the purposes for which personal information is collected, used, and retained.
- Documented purposes of processing in the notice
- Purposes vague or undisclosed
Organisation establishes agreements with data subjects and third parties regarding the handling of personal information.
- Executed agreements capturing consent
- Re-consent process on changes (N2.2)
- No agreement capturing consent for PI use
Collection and Creation
Personal information is collected by lawful and fair means with the knowledge or consent of the data subject.
- Lawful-basis determination for collection
- Options communicated to data subjects
- Collection without a lawful basis
Collection of personal information is limited to that which is necessary for the identified purposes.
- Data-minimisation rules limiting collection to stated purposes
- Excessive collection beyond stated purposes
Organisation obtains implicit or explicit consent as appropriate for the type of personal information collected.
- Explicit/implicit consent records
- Explicit consent for sensitive PI
- Sensitive PI collected without explicit consent
Data Integrity and Quality
Organisation maintains accurate, complete, and relevant personal information for the purposes for which it is used.
- Accuracy validation & data-subject confirmation processes
- Inaccurate or stale PI not corrected
Organisation has processes to verify and correct inaccurate or incomplete personal information.
- Periodic re-validation of PI completeness & correctness
- No data-quality re-validation process
Disclosure to Third Parties
Personal information is disclosed to third parties only for identified purposes and with appropriate consent.
- Disclosure-with-consent controls
- Record of authorised disclosures (D6.2)
- PI disclosed without consent or record
Organisation requires third-party recipients to protect personal information consistent with its privacy commitments.
- Vendor privacy commitments & DPAs
- Periodic third-party compliance assessment
- Third parties handle PI without binding commitments
Organisation remains accountable for personal information transferred to third parties.
- Cross-border transfer safeguards (adequacy/SCCs/BCRs)
- Breach-notification commitments from vendors (D6.5)
- Onward transfers without safeguards
Monitoring and Enforcement
Organisation monitors compliance with its privacy policies, procedures, and commitments on an ongoing basis.
- Ongoing & separate evaluations of privacy controls
- No monitoring of privacy compliance
Organisation has processes for receiving and addressing privacy-related inquiries and complaints from data subjects.
- Inquiry/complaint/dispute handling & resolution records
- No complaint-handling mechanism
Organisation takes corrective action to address privacy program deficiencies identified through monitoring or complaints.
- Non-compliance remediation & corrective-action records
- Identified privacy gaps not remediated
Privacy Management
Organisation establishes governance structure with defined roles, responsibilities, and accountability for the privacy program.
- Documented privacy governance structure & accountability
- Assigned privacy roles/responsibilities
- No accountable owner for the privacy program
Organisation documents and maintains privacy policies and procedures that reflect applicable laws and commitments.
- Documented privacy policies & procedures
- Policy communication records
- Privacy policies undocumented or not communicated
Organisation conducts assessments to identify and evaluate privacy risks arising from data processing activities.
- Privacy (risk) impact assessments
- PI classification register
- No privacy impact assessment performed
Organisation has processes to detect, respond to, and recover from privacy incidents and breaches.
- Privacy incident & breach response plan
- Breach notification procedure
- No incident/breach response plan
Security for Privacy
Organisation maintains an information security program to protect personal information against unauthorised access and disclosure.
- Logical access security controls
- Asset inventory & access logging
- Inadequate logical access controls over PI
Technical and organisational safeguards are implemented commensurate with the sensitivity of the personal information.
- Physical access restrictions
- Encryption of PI in transit and at rest
- PI unencrypted or physically unprotected
Organisation regularly tests and monitors the effectiveness of security safeguards protecting personal information.
- Security testing/monitoring of privacy controls
- Anti-malware coverage
- No testing/monitoring of privacy security controls
Use, Retention, and Disposal
Personal information is used only for the purposes identified in the privacy notice or as otherwise agreed.
- Use limited to collected purposes
- New-purpose consent records
- PI used for incompatible new purposes
Organisation retains personal information only for as long as necessary to fulfil stated purposes or legal obligations.
- Retention schedule (no longer than necessary)
- PI retained beyond necessity
Organisation securely disposes of personal information when it is no longer needed for the identified purposes.
- Deletion-request capture & secure destruction records
- PI not securely destroyed when no longer needed
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the AICPA Privacy Management Framework (PMF) framework page.