Skip to content

Evidence request lists

ASEAN Data Management Framework

Evidence request list. 27 controls, 27 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Controls

ADMF-5.1
Implement risk-based protection controls

Implement preventive and detective controls commensurate with the potential impact of data being compromised, establishing risk tolerance and selecting controls to bring risk within the risk appetite.

Artefacts an auditor will ask for
  • Control set mapped to dataset tiers
  • Risk tolerance/appetite statement driving control selection
  • Evidence controls are operating
Where this commonly fails
  • Uniform controls regardless of tier
  • No link between control strength and impact
  • Controls designed but not operating
ADMF-5.2
Apply technical, procedural and physical safeguards

Apply technical (IT controls), procedural (baseline and design) and physical safeguards to ensure confidentiality, integrity and availability of data at all stages of the data lifecycle.

Artefacts an auditor will ask for
  • Inventory of technical, procedural and physical safeguards
  • Mapping of safeguards to CIA objectives
  • Evidence safeguards cover hardcopy and digital data
Where this commonly fails
  • Only technical controls considered
  • Physical/hardcopy data unprotected
  • Procedural safeguards undocumented
ADMF-5.3
Protect data across the data lifecycle

Apply protection appropriate to each data lifecycle stage, creation, distribution, storage and disposal, e.g. MFA and encryption at creation, encryption and DLP in transit, end-point encryption and DR for storage, and media sanitisation prior to disposal.

Artefacts an auditor will ask for
  • Lifecycle-stage control mapping (creation/distribution/storage/disposal)
  • Evidence of encryption, DLP, backup/DR and sanitisation as applicable
  • Disposal/sanitisation records
Where this commonly fails
  • Controls only at rest, transit and disposal ignored
  • No secure disposal/sanitisation
  • Lifecycle stages not distinguished
ADMF-5.4
Build a data protection control matrix

Document a data protection control matrix that specifies the controls applied for each category/tier across the data lifecycle stages.

Artefacts an auditor will ask for
  • Data protection control matrix (tier x lifecycle stage)
  • Approval and version history of the matrix
  • Evidence matrix is applied operationally
Where this commonly fails
  • No documented mapping of controls to tiers and stages
  • Matrix not maintained
  • Matrix exists but is not operationalised
ADMF-5.5
Manage and accept residual risk

Assess residual risk remaining after controls and have management formally assess and accept it through a risk acceptance process.

Artefacts an auditor will ask for
  • Residual risk register
  • Documented management risk-acceptance decisions
  • Evidence residual risk is within risk appetite
Where this commonly fails
  • Residual risk not assessed
  • No formal acceptance by management
  • Accepted risks not tracked or reviewed
ADMF-5.6
Reference recognised security and privacy standards

Use recognised international standards as reference when categorising and protecting data, e.g. NIST SP 800-60, FIPS 199, NIST CSF/RMF, ISO 9001, ISO/IEC 27001, 27018 and 27701.

Artefacts an auditor will ask for
  • Documented references to standards used (e.g. ISO 27001, NIST CSF/RMF, FIPS 199)
  • Mapping of internal categories to referenced standards
  • Justification where standards are adapted
Where this commonly fails
  • No reference to external standards
  • Standards cited but not actually applied
  • Adaptations from standards undocumented

Data Inventory

ADMF-3.1
Identify and understand organisational data

Begin with identification of the data the organisation possesses by answering why data is collected/used/stored, who is responsible, what type of data, where it is located and how it is accessed; update understanding as new data types arise.

Artefacts an auditor will ask for
  • Data identification questionnaire (why/who/what/where/how) completed
  • Evidence of periodic re-identification of new data types
  • Mapping of responsible owners to data
Where this commonly fails
  • Only known systems mapped, shadow data omitted
  • Data ownership not assigned
  • No trigger to capture newly collected data types
ADMF-3.2
Maintain a data inventory

Capture in a data inventory, for each dataset, the purpose, data owner, data type (personal or business), data fields, dataset and location/system; keep the inventory updated as new data types are collected.

Artefacts an auditor will ask for
  • Data inventory register with purpose, owner, type, fields, dataset and location
  • Update log showing the inventory is maintained
  • Coverage check across business units
Where this commonly fails
  • Inventory missing key attributes (owner, purpose, location)
  • Personal vs business data not distinguished
  • Inventory stale or partial
ADMF-3.3
Apply overarching categorisation considerations

When categorising and protecting data consider nature and type of services provided, applicable regulation (e.g. PDPA, GDPR, sector rules), competitive landscape, cost of safeguards versus risk appetite (including data aggregation and volume), and customer expectations.

Artefacts an auditor will ask for
  • Documented categorisation considerations applied per dataset
  • Regulatory mapping (PDPA/GDPR/sector) influencing categories
  • Rationale balancing safeguard cost against risk appetite
Where this commonly fails
  • Categories assigned without considering regulation
  • Aggregation/volume effects ignored
  • Over-protection that hinders legitimate data use

Governance and Oversight

ADMF-1.1
Establish data management governance functions

Identify and determine roles and responsibilities across three functions, data management, business process and risk management, to ensure adoption, operation and compliance of the DMF in line with business needs.

Artefacts an auditor will ask for
  • Org chart or RACI assigning data management, business process and risk management functions
  • Documented mandate/terms of reference for each function
  • Board or owner approval of the governance structure
Where this commonly fails
  • Functions defined on paper but not staffed or empowered
  • No risk management function separate from operations
  • Small-organisation roles undocumented and undelegated
ADMF-1.2
Data management function responsibilities

The data management function owns and designs the processes supporting the six components, defines policies and procedures, determines implementation roles and skills, promotes awareness, reviews dataset categories, manages risk by establishing protection controls, and handles data protection queries and complaints.

Artefacts an auditor will ask for
  • Documented process ownership for the six DMF components
  • Awareness/training distribution records
  • Log of data-protection queries and complaints with resolution
Where this commonly fails
  • No single accountable owner for the DMF processes
  • Awareness activities not evidenced
  • Category reviews not performed by the data management function
ADMF-1.3
Business process function responsibilities

The business process function identifies data and completes the data inventory, implements protection controls and complies with defined policies and procedures, and reports any security incident or non-compliance.

Artefacts an auditor will ask for
  • Completed data inventory attributable to business units
  • Evidence controls are operated by process owners
  • Incident/non-compliance reports raised by business functions
Where this commonly fails
  • Inventory completed centrally without business-unit input
  • Controls defined but not operated by process owners
  • Incidents not reported up to the risk function
ADMF-1.4
Risk management function responsibilities

The risk management function monitors implementation of effective data risk-management practices to keep risk within the organisation's risk appetite, evaluates control effectiveness, and reports findings to management with recommendations to improve policies.

Artefacts an auditor will ask for
  • Risk monitoring reports against risk appetite
  • Control effectiveness evaluations
  • Findings and improvement recommendations to management
Where this commonly fails
  • No independent evaluation of control effectiveness
  • Risk appetite not used as a monitoring threshold
  • Findings not reported to management
ADMF-1.5
Executive direction and risk appetite

Leadership (business owner or executive management) establishes risk appetite and strategy, approves the content of the six foundational components, and oversees the function to confirm it operates as designed.

Artefacts an auditor will ask for
  • Documented risk appetite and data strategy approved by leadership
  • Sign-off of the six DMF components
  • Oversight/management review records
Where this commonly fails
  • Risk appetite undefined or not approved at leadership level
  • Components implemented without executive sign-off
  • No oversight to confirm the function operates as designed

Impact / Risk Assessment

ADMF-4.1
Establish a data categorisation matrix

Define a categorisation matrix with impact categories, thresholds and tiers that provides clear guidance on assigning datasets by risk impact level; the number of tiers depends on business needs (non-prescriptive).

Artefacts an auditor will ask for
  • Documented categorisation matrix with tiers and thresholds
  • Guidance on assigning datasets to tiers
  • Approval of the matrix by the data management function
Where this commonly fails
  • No defined tiers or thresholds
  • Matrix not applied consistently
  • Tier definitions ambiguous
ADMF-4.2
Assess confidentiality, integrity and availability impact

Assess the impact if a dataset is compromised across confidentiality (unauthorised disclosure), integrity (quality/corruption) and availability (not available to intended users).

Artefacts an auditor will ask for
  • Impact assessment recording C, I and A impact per dataset
  • Definitions of confidentiality, integrity and availability impact
  • Linkage of CIA impact to assigned tier
Where this commonly fails
  • Only confidentiality considered, integrity/availability omitted
  • CIA impact not recorded per dataset
  • Assessment not repeated when data changes
ADMF-4.3
Assess business impact categories

Assess impact across the primary impact categories, financial, strategic, operational and compliance (and reputational/legal), to inform the tier assigned to each dataset.

Artefacts an auditor will ask for
  • Impact assessment across financial, strategic, operational and compliance categories
  • Evidence categories feed the tier assignment
  • Stakeholder input into impact ratings
Where this commonly fails
  • Impact assessed on a single dimension
  • Compliance/legal impact not considered
  • No traceability from impact to tier
ADMF-4.4
Assign datasets to risk tiers

Assign each dataset to a tier (e.g. Tier 1 significant, Tier 2 moderate, Tier 3 limited harm) based on the assessed impact, avoiding over-protection that hinders business use of data.

Artefacts an auditor will ask for
  • Register of datasets with assigned tiers
  • Rationale for each tier assignment
  • Review evidence that tiers remain appropriate
Where this commonly fails
  • Datasets unassigned or default-tiered
  • Tiers assigned without documented rationale
  • Over-classification across the board

Monitoring and Continuous Improvement

ADMF-6.1
Define monitoring and measurement scope

Determine what needs to be monitored and measured, the methods of monitoring/measurement/analysis/evaluation, when monitoring and measurement are performed and by whom, and when results are analysed and evaluated.

Artefacts an auditor will ask for
  • Documented monitoring plan (what/how/when/who)
  • Defined metrics and evaluation cadence
  • Assigned monitoring responsibilities
Where this commonly fails
  • Monitoring undefined or ad hoc
  • No metrics or evaluation schedule
  • Responsibility for monitoring unassigned
ADMF-6.2
Review controls associated with each category

Periodically review the design of the process for assigning categories and the data protection controls matrix, taking into account security audits, incidents, effectiveness measurements and business feedback.

Artefacts an auditor will ask for
  • Periodic review records of categorisation process and control matrix
  • Inputs from audits, incidents and effectiveness measures
  • Resulting design changes
Where this commonly fails
  • Control matrix never reviewed
  • Audit/incident learnings not fed back
  • Reviews not evidenced
ADMF-6.3
Review categories assigned to datasets

Periodically review the categories assigned to datasets and the current lifecycle stage for each, adjusting tiers as data, use or context changes.

Artefacts an auditor will ask for
  • Periodic re-categorisation review records
  • Evidence tiers updated when data/use changes
  • Lifecycle status tracked per dataset
Where this commonly fails
  • Categories set once and never revisited
  • Lifecycle stage not tracked
  • Re-categorisation not triggered by change
ADMF-6.4
Test data protection control effectiveness

Test the operating effectiveness of data protection controls and measure effectiveness to verify that security requirements have been met.

Artefacts an auditor will ask for
  • Control effectiveness test results
  • Defined effectiveness measures/requirements
  • Remediation of failed tests
Where this commonly fails
  • Controls assumed effective without testing
  • No defined effectiveness criteria
  • Test failures not remediated
ADMF-6.5
Update policies, procedures and processes

Incorporate findings from monitoring and review activities into updated policies, procedures and processes to drive continuous improvement of data management.

Artefacts an auditor will ask for
  • Change log showing updates driven by monitoring findings
  • Updated policies/procedures with version history
  • Evidence of communication of changes
Where this commonly fails
  • Findings not translated into updates
  • Policies static despite review findings
  • Updates not communicated

Policies and Procedures

ADMF-2.1
Leadership commitment in policy (who)

Management provides documented commitment to the establishment, implementation, operation, monitoring, review, maintenance and improvement of data management initiatives.

Artefacts an auditor will ask for
  • Approved data management policy with leadership endorsement
  • Statement of management commitment
  • Review/version history of the policy
Where this commonly fails
  • Policy lacks leadership endorsement
  • Commitment stated once and never reviewed
  • No named policy owner
ADMF-2.2
Define objectives, scope and considerations (what and why)

The objectives, scope of application and considerations of the DMF are defined, documented and maintained to enable a clear understanding of the implementation parameters specific to the organisation.

Artefacts an auditor will ask for
  • Documented DMF objectives and scope
  • Defined considerations specific to the organisation
  • Maintenance/review evidence of scope statements
Where this commonly fails
  • Scope undocumented or generic
  • Objectives not tied to the organisation's data context
  • Scope never revisited as the business changes
ADMF-2.3
Establish the data management approach (how)

Adopt an effective data management approach to define, establish, monitor and maintain data management, including formalising the activities that categorise and protect datasets and provide for their continued improvement.

Artefacts an auditor will ask for
  • Documented data management approach/methodology
  • Formalised categorisation and protection procedures
  • Continuous improvement mechanism in procedure
Where this commonly fails
  • Approach implied but not formalised
  • Categorisation and protection steps not described procedurally
  • No improvement loop in procedures
ADMF-2.4
Embed data management in corporate governance and policy

Include data management policies as part of corporate governance to ensure a clear mandate and accountability, and reflect the subsequent foundational components as content within the policies and procedures.

Artefacts an auditor will ask for
  • Data management policy referenced within corporate governance framework
  • Policies reflecting inventory, assessment, controls and monitoring components
  • Distribution to internal and external stakeholders
Where this commonly fails
  • Policy isolated from corporate governance
  • Components 3-6 not reflected in policy content
  • Policies not communicated to suppliers/employees
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ASEAN Data Management Framework framework page.