Skip to content

Evidence request lists

AICPA Privacy Management Framework (PMF)

Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Access

PMF-A.1
Individual Access Rights

Data subjects can access, review, and request corrections to their personal information held by the organisation.

Artefacts an auditor will ask for
  • Access-request handling with identity authentication
  • Provision of PI in understandable form
Where this commonly fails
  • No mechanism for data subjects to access their PI
PMF-A.2
Access Request Process

Organisation has procedures for authenticating data subjects and responding to access requests in a timely manner.

Artefacts an auditor will ask for
  • Correction/amendment process
  • Notification of corrections to third parties
Where this commonly fails
  • Correction requests not actioned

Agreement, Notice, and Communication

PMF-AN.1
Privacy Notice

Organisation provides clear and conspicuous notice about its privacy practices to data subjects.

Artefacts an auditor will ask for
  • Clear, conspicuous privacy notice
  • Notice content covering required items
Where this commonly fails
  • No privacy notice provided to data subjects
PMF-AN.2
Purpose Specification

Organisation specifies the purposes for which personal information is collected, used, and retained.

Artefacts an auditor will ask for
  • Documented purposes of processing in the notice
Where this commonly fails
  • Purposes vague or undisclosed
PMF-AN.3
Privacy Agreements

Organisation establishes agreements with data subjects and third parties regarding the handling of personal information.

Artefacts an auditor will ask for
  • Executed agreements capturing consent
  • Re-consent process on changes (N2.2)
Where this commonly fails
  • No agreement capturing consent for PI use

Collection and Creation

PMF-CC.1
Lawful and Fair Collection

Personal information is collected by lawful and fair means with the knowledge or consent of the data subject.

Artefacts an auditor will ask for
  • Lawful-basis determination for collection
  • Options communicated to data subjects
Where this commonly fails
  • Collection without a lawful basis
PMF-CC.2
Collection Limitation

Collection of personal information is limited to that which is necessary for the identified purposes.

Artefacts an auditor will ask for
  • Data-minimisation rules limiting collection to stated purposes
Where this commonly fails
  • Excessive collection beyond stated purposes
PMF-CC.3
Consent Mechanisms

Organisation obtains implicit or explicit consent as appropriate for the type of personal information collected.

Artefacts an auditor will ask for
  • Explicit/implicit consent records
  • Explicit consent for sensitive PI
Where this commonly fails
  • Sensitive PI collected without explicit consent

Data Integrity and Quality

PMF-DI.1
Data Accuracy

Organisation maintains accurate, complete, and relevant personal information for the purposes for which it is used.

Artefacts an auditor will ask for
  • Accuracy validation & data-subject confirmation processes
Where this commonly fails
  • Inaccurate or stale PI not corrected
PMF-DI.2
Data Quality Processes

Organisation has processes to verify and correct inaccurate or incomplete personal information.

Artefacts an auditor will ask for
  • Periodic re-validation of PI completeness & correctness
Where this commonly fails
  • No data-quality re-validation process

Disclosure to Third Parties

PMF-D.1
Third-Party Disclosure Controls

Personal information is disclosed to third parties only for identified purposes and with appropriate consent.

Artefacts an auditor will ask for
  • Disclosure-with-consent controls
  • Record of authorised disclosures (D6.2)
Where this commonly fails
  • PI disclosed without consent or record
PMF-D.2
Third-Party Agreements

Organisation requires third-party recipients to protect personal information consistent with its privacy commitments.

Artefacts an auditor will ask for
  • Vendor privacy commitments & DPAs
  • Periodic third-party compliance assessment
Where this commonly fails
  • Third parties handle PI without binding commitments
PMF-D.3
Onward Transfer Accountability

Organisation remains accountable for personal information transferred to third parties.

Artefacts an auditor will ask for
  • Cross-border transfer safeguards (adequacy/SCCs/BCRs)
  • Breach-notification commitments from vendors (D6.5)
Where this commonly fails
  • Onward transfers without safeguards

Monitoring and Enforcement

PMF-ME.1
Privacy Program Monitoring

Organisation monitors compliance with its privacy policies, procedures, and commitments on an ongoing basis.

Artefacts an auditor will ask for
  • Ongoing & separate evaluations of privacy controls
Where this commonly fails
  • No monitoring of privacy compliance
PMF-ME.2
Complaint Handling

Organisation has processes for receiving and addressing privacy-related inquiries and complaints from data subjects.

Artefacts an auditor will ask for
  • Inquiry/complaint/dispute handling & resolution records
Where this commonly fails
  • No complaint-handling mechanism
PMF-ME.3
Enforcement and Remediation

Organisation takes corrective action to address privacy program deficiencies identified through monitoring or complaints.

Artefacts an auditor will ask for
  • Non-compliance remediation & corrective-action records
Where this commonly fails
  • Identified privacy gaps not remediated

Privacy Management

PMF-M.1
Privacy Program Governance

Organisation establishes governance structure with defined roles, responsibilities, and accountability for the privacy program.

Artefacts an auditor will ask for
  • Documented privacy governance structure & accountability
  • Assigned privacy roles/responsibilities
Where this commonly fails
  • No accountable owner for the privacy program
PMF-M.2
Privacy Policies and Procedures

Organisation documents and maintains privacy policies and procedures that reflect applicable laws and commitments.

Artefacts an auditor will ask for
  • Documented privacy policies & procedures
  • Policy communication records
Where this commonly fails
  • Privacy policies undocumented or not communicated
PMF-M.3
Privacy Risk Assessment

Organisation conducts assessments to identify and evaluate privacy risks arising from data processing activities.

Artefacts an auditor will ask for
  • Privacy (risk) impact assessments
  • PI classification register
Where this commonly fails
  • No privacy impact assessment performed
PMF-M.4
Privacy Incident Management

Organisation has processes to detect, respond to, and recover from privacy incidents and breaches.

Artefacts an auditor will ask for
  • Privacy incident & breach response plan
  • Breach notification procedure
Where this commonly fails
  • No incident/breach response plan

Security for Privacy

PMF-SP.1
Information Security Program

Organisation maintains an information security program to protect personal information against unauthorised access and disclosure.

Artefacts an auditor will ask for
  • Logical access security controls
  • Asset inventory & access logging
Where this commonly fails
  • Inadequate logical access controls over PI
PMF-SP.2
Security Safeguards

Technical and organisational safeguards are implemented commensurate with the sensitivity of the personal information.

Artefacts an auditor will ask for
  • Physical access restrictions
  • Encryption of PI in transit and at rest
Where this commonly fails
  • PI unencrypted or physically unprotected
PMF-SP.3
Security Testing and Monitoring

Organisation regularly tests and monitors the effectiveness of security safeguards protecting personal information.

Artefacts an auditor will ask for
  • Security testing/monitoring of privacy controls
  • Anti-malware coverage
Where this commonly fails
  • No testing/monitoring of privacy security controls

Use, Retention, and Disposal

PMF-URD.1
Use Limitation

Personal information is used only for the purposes identified in the privacy notice or as otherwise agreed.

Artefacts an auditor will ask for
  • Use limited to collected purposes
  • New-purpose consent records
Where this commonly fails
  • PI used for incompatible new purposes
PMF-URD.2
Retention Periods

Organisation retains personal information only for as long as necessary to fulfil stated purposes or legal obligations.

Artefacts an auditor will ask for
  • Retention schedule (no longer than necessary)
Where this commonly fails
  • PI retained beyond necessity
PMF-URD.3
Secure Disposal

Organisation securely disposes of personal information when it is no longer needed for the identified purposes.

Artefacts an auditor will ask for
  • Deletion-request capture & secure destruction records
Where this commonly fails
  • PI not securely destroyed when no longer needed
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the AICPA Privacy Management Framework (PMF) framework page.