Australia Consumer Data Right - Banking (CDR)
Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Information Security (Schedule 2)
Have processes to limit the risk of inappropriate or unauthorised access to the CDR data environment, including MFA or equivalent, restriction of administrative privileges, audit logging and monitoring, access security, limiting physical access, role-based access, unique IDs and password authentication.
- MFA/equivalent and privileged-access restriction evidence
- Audit logging and monitoring records
- Role-based access and unique-ID configuration
- No MFA on the CDR data environment
- Admin privileges unrestricted
- No audit logging/monitoring
Take steps to secure the network and systems within the data environment, including encryption, firewalls, server hardening and hardening of end-user devices.
- Encryption configuration
- Firewall rules and segmentation
- Server and end-user device hardening baselines
- Unencrypted CDR data flows
- No firewall/segmentation
- Systems not hardened
Securely manage information assets within the CDR data environment over their lifecycle, including data loss prevention, controls over CDR data in non-production environments, and information asset lifecycle management.
- DLP controls
- Controls over CDR data in non-production environments
- Asset lifecycle/disposal records
- CDR data in test/non-prod unprotected
- No DLP
- No asset lifecycle management
Implement a formal vulnerability management program to identify, track and remediate vulnerabilities in the CDR data environment in a timely manner, including security patching and secure coding.
- Vulnerability management program and register
- Patching cadence and records
- Secure coding practices
- No vulnerability management program
- Patching not timely
- Insecure development
Take steps to limit, prevent, detect and remove malware in the CDR data environment, including anti-malware/antivirus, web and email content filtering, and application whitelisting.
- Anti-malware deployment
- Web/email content filtering
- Application whitelisting configuration
- No anti-malware on the data environment
- No content filtering
- Unrestricted application execution
Implement a formal information security training and awareness program for all personnel interacting with CDR data, including security training and awareness, acceptable use of technology, and human resource security.
- Security training and awareness records
- Acceptable use policy
- HR security (screening, onboarding/offboarding)
- No security training for CDR personnel
- No acceptable use policy
- No HR security controls
Establish a formal governance framework for CDR data information security risk, document practices and responsibilities including those of senior management, maintain an information security policy, and review the framework at least annually.
- Approved CDR information security governance framework
- Documented roles and responsibilities including senior management accountabilities
- Information security policy covering risk posture and control design
- Dated review records showing annual or change driven review
- Evidence of budget and resource allocation and management oversight
- Generic corporate security policy with no CDR specific risk posture
- Senior management responsibilities undefined
- Framework never reviewed after accreditation
Assess, define and document the boundaries of the CDR data environment and review them for completeness and accuracy at least annually or on becoming aware of material change.
- Documented CDR data environment boundary definition
- Data flow diagrams and system inventory showing what is in and out of scope
- Dated boundary review records
- Change records showing boundary updates after system or supplier change
- Evidence outsourced providers are placed inside or outside the boundary deliberately
- Boundary defined once at accreditation and never revisited
- Cloud services and outsourced providers omitted from the boundary
- No linkage between change management and boundary review
Maintain an information security capability that complies with the Part 2 minimum controls and is adapted to the threats, the CDR data held and the potential consumer harm, and review and adjust it at least annually.
- Mapping of the capability to each Part 2 minimum control
- Risk assessment considering threats, data held and consumer harm
- Dated capability review and adjustment records
- Evidence of capability changes following a risk reassessment
- Part 2 controls implemented with no assessment of consumer harm
- Capability treated as static once the Part 2 checklist is met
- Review performed but no adjustments ever result
Establish and implement a testing program that assesses the effectiveness of the information security capability, monitor and evaluate control design and operating effectiveness, escalate deficiencies to senior management, use independent skilled testers, and review the program at least annually.
- Documented controls testing program with scope and frequency rationale
- Test results covering design, implementation and operating effectiveness
- Evidence testers were skilled and independent of control performance
- Escalation and reporting of deficiencies to senior management with remediation tracking
- Dated review of the sufficiency of the testing program
- Testing performed by the same team that operates the controls
- Only design tested and never operating effectiveness
- Deficiencies recorded but never escalated to senior management
- Testing frequency not justified against threat change or prior results
Maintain procedures to detect, record and respond to information security incidents, maintain CDR data security response plans covering the full incident lifecycle and the required notifications, and review and test those plans at least annually.
- Incident detection, recording and response procedures
- CDR data security response plans covering plausible incident scenarios
- Notification procedures naming the Information Commissioner, affected consumers and the Australian Cyber Security Centre with the 30 day limit
- Records of plan tests or exercises and lessons captured
- Incident register with timelines from detection to post incident review
- Response plan omits the Australian Cyber Security Centre notification or its 30 day limit
- Plans written but never tested
- No post incident review stage
- Notifiable data breach process not linked to the CDR specific plan
Privacy Safeguards
Manage CDR data in an open and transparent way, including having a clearly expressed and up-to-date CDR policy.
- Published CDR policy
- Evidence of open data-handling practices
- No CDR policy
- Policy out of date or inaccessible
Notify the consumer of disclosures of CDR data, including via the consumer dashboard.
- Disclosure notifications / dashboard entries
- Records of disclosures notified
- Disclosures not notified
- Dashboard not updated
Take reasonable steps to ensure CDR data is accurate, up to date and complete having regard to the purpose.
- Data quality checks
- Correction processes feeding quality
- No data quality controls
- Inaccurate data used in decisions
Protect CDR data from misuse, interference, loss and unauthorised access, and destroy or de-identify redundant CDR data.
- Information security controls (Schedule 2)
- Redundant-data destruction/de-identification records
- Redundant CDR data retained
- Security controls not applied to CDR data
Correct CDR data on request or when satisfied it is inaccurate, out of date, incomplete, irrelevant or misleading.
- Correction request process
- Records of corrections made
- No correction mechanism
- Correction requests not actioned
Give individuals the option of not identifying themselves, or of using a pseudonym, where lawful and practicable.
- Anonymity/pseudonymity options where applicable
- Assessment of practicability
- No anonymity option considered
- Identification required without justification
Only seek to collect CDR data with valid consent and in accordance with the CDR Rules.
- Valid consent records before collection
- Collection limited to consented scope
- Collection without valid consent
- Over-collection beyond consent
Where unsolicited CDR data is received, determine whether it could have been collected and, if not, destroy or de-identify it.
- Process for handling unsolicited CDR data
- Destruction/de-identification records
- Unsolicited data retained without assessment
- No handling procedure
Notify the consumer of the collection of CDR data, including via the consumer dashboard and a CDR receipt.
- Collection notifications / CDR receipts
- Consumer dashboard entries
- Collection not notified
- No CDR receipt provided
Only use or disclose CDR data in accordance with consent and the CDR Rules.
- Use/disclosure tied to consent
- Logs of use and disclosure
- Use/disclosure beyond consent
- No traceability of use
Do not use or disclose CDR data for direct marketing except as permitted by the CDR Rules.
- Controls preventing unauthorised direct marketing
- Consent basis for any permitted marketing
- CDR data used for marketing without basis
- No opt-out honoured
Before disclosing CDR data overseas, take reasonable steps to ensure the overseas recipient complies with the safeguards.
- Overseas disclosure assessment
- Contractual safeguards with overseas recipients
- Overseas disclosure without safeguards
- No assessment of recipient compliance
Do not adopt, use or disclose a government related identifier as the individual's own identifier except as permitted.
- Controls on government identifier use
- Justification where permitted
- Government identifier used as own identifier
- No control over identifier handling
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Australia Consumer Data Right - Banking (CDR) framework page.