Skip to content

Evidence request lists

Australia Consumer Data Right - Banking (CDR)

Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Information Security (Schedule 2)

AUCDR-IS-1
Limit risk of unauthorised access to the CDR data environment

Have processes to limit the risk of inappropriate or unauthorised access to the CDR data environment, including MFA or equivalent, restriction of administrative privileges, audit logging and monitoring, access security, limiting physical access, role-based access, unique IDs and password authentication.

Artefacts an auditor will ask for
  • MFA/equivalent and privileged-access restriction evidence
  • Audit logging and monitoring records
  • Role-based access and unique-ID configuration
Where this commonly fails
  • No MFA on the CDR data environment
  • Admin privileges unrestricted
  • No audit logging/monitoring
AUCDR-IS-2
Secure the network and systems within the data environment

Take steps to secure the network and systems within the data environment, including encryption, firewalls, server hardening and hardening of end-user devices.

Artefacts an auditor will ask for
  • Encryption configuration
  • Firewall rules and segmentation
  • Server and end-user device hardening baselines
Where this commonly fails
  • Unencrypted CDR data flows
  • No firewall/segmentation
  • Systems not hardened
AUCDR-IS-3
Securely manage information assets over their lifecycle

Securely manage information assets within the CDR data environment over their lifecycle, including data loss prevention, controls over CDR data in non-production environments, and information asset lifecycle management.

Artefacts an auditor will ask for
  • DLP controls
  • Controls over CDR data in non-production environments
  • Asset lifecycle/disposal records
Where this commonly fails
  • CDR data in test/non-prod unprotected
  • No DLP
  • No asset lifecycle management
AUCDR-IS-4
Formal vulnerability management program

Implement a formal vulnerability management program to identify, track and remediate vulnerabilities in the CDR data environment in a timely manner, including security patching and secure coding.

Artefacts an auditor will ask for
  • Vulnerability management program and register
  • Patching cadence and records
  • Secure coding practices
Where this commonly fails
  • No vulnerability management program
  • Patching not timely
  • Insecure development
AUCDR-IS-5
Limit, prevent, detect and remove malware

Take steps to limit, prevent, detect and remove malware in the CDR data environment, including anti-malware/antivirus, web and email content filtering, and application whitelisting.

Artefacts an auditor will ask for
  • Anti-malware deployment
  • Web/email content filtering
  • Application whitelisting configuration
Where this commonly fails
  • No anti-malware on the data environment
  • No content filtering
  • Unrestricted application execution
AUCDR-IS-6
Information security training and awareness program

Implement a formal information security training and awareness program for all personnel interacting with CDR data, including security training and awareness, acceptable use of technology, and human resource security.

Artefacts an auditor will ask for
  • Security training and awareness records
  • Acceptable use policy
  • HR security (screening, onboarding/offboarding)
Where this commonly fails
  • No security training for CDR personnel
  • No acceptable use policy
  • No HR security controls
AUCDR-IS-STEP1
Step 1 - Define and implement security governance for CDR data

Establish a formal governance framework for CDR data information security risk, document practices and responsibilities including those of senior management, maintain an information security policy, and review the framework at least annually.

Artefacts an auditor will ask for
  • Approved CDR information security governance framework
  • Documented roles and responsibilities including senior management accountabilities
  • Information security policy covering risk posture and control design
  • Dated review records showing annual or change driven review
  • Evidence of budget and resource allocation and management oversight
Where this commonly fails
  • Generic corporate security policy with no CDR specific risk posture
  • Senior management responsibilities undefined
  • Framework never reviewed after accreditation
AUCDR-IS-STEP2
Step 2 - Define the boundaries of the CDR data environment

Assess, define and document the boundaries of the CDR data environment and review them for completeness and accuracy at least annually or on becoming aware of material change.

Artefacts an auditor will ask for
  • Documented CDR data environment boundary definition
  • Data flow diagrams and system inventory showing what is in and out of scope
  • Dated boundary review records
  • Change records showing boundary updates after system or supplier change
  • Evidence outsourced providers are placed inside or outside the boundary deliberately
Where this commonly fails
  • Boundary defined once at accreditation and never revisited
  • Cloud services and outsourced providers omitted from the boundary
  • No linkage between change management and boundary review
AUCDR-IS-STEP3
Step 3 - Have and maintain an information security capability

Maintain an information security capability that complies with the Part 2 minimum controls and is adapted to the threats, the CDR data held and the potential consumer harm, and review and adjust it at least annually.

Artefacts an auditor will ask for
  • Mapping of the capability to each Part 2 minimum control
  • Risk assessment considering threats, data held and consumer harm
  • Dated capability review and adjustment records
  • Evidence of capability changes following a risk reassessment
Where this commonly fails
  • Part 2 controls implemented with no assessment of consumer harm
  • Capability treated as static once the Part 2 checklist is met
  • Review performed but no adjustments ever result
AUCDR-IS-STEP4
Step 4 - Implement a formal controls assessment program

Establish and implement a testing program that assesses the effectiveness of the information security capability, monitor and evaluate control design and operating effectiveness, escalate deficiencies to senior management, use independent skilled testers, and review the program at least annually.

Artefacts an auditor will ask for
  • Documented controls testing program with scope and frequency rationale
  • Test results covering design, implementation and operating effectiveness
  • Evidence testers were skilled and independent of control performance
  • Escalation and reporting of deficiencies to senior management with remediation tracking
  • Dated review of the sufficiency of the testing program
Where this commonly fails
  • Testing performed by the same team that operates the controls
  • Only design tested and never operating effectiveness
  • Deficiencies recorded but never escalated to senior management
  • Testing frequency not justified against threat change or prior results
AUCDR-IS-STEP5
Step 5 - Manage and report security incidents

Maintain procedures to detect, record and respond to information security incidents, maintain CDR data security response plans covering the full incident lifecycle and the required notifications, and review and test those plans at least annually.

Artefacts an auditor will ask for
  • Incident detection, recording and response procedures
  • CDR data security response plans covering plausible incident scenarios
  • Notification procedures naming the Information Commissioner, affected consumers and the Australian Cyber Security Centre with the 30 day limit
  • Records of plan tests or exercises and lessons captured
  • Incident register with timelines from detection to post incident review
Where this commonly fails
  • Response plan omits the Australian Cyber Security Centre notification or its 30 day limit
  • Plans written but never tested
  • No post incident review stage
  • Notifiable data breach process not linked to the CDR specific plan

Privacy Safeguards

AUCDR-PS-1
Privacy Safeguard 1 - Open and transparent management of CDR data

Manage CDR data in an open and transparent way, including having a clearly expressed and up-to-date CDR policy.

Artefacts an auditor will ask for
  • Published CDR policy
  • Evidence of open data-handling practices
Where this commonly fails
  • No CDR policy
  • Policy out of date or inaccessible
AUCDR-PS-10
Privacy Safeguard 10 - Notifying of the disclosure of CDR data

Notify the consumer of disclosures of CDR data, including via the consumer dashboard.

Artefacts an auditor will ask for
  • Disclosure notifications / dashboard entries
  • Records of disclosures notified
Where this commonly fails
  • Disclosures not notified
  • Dashboard not updated
AUCDR-PS-11
Privacy Safeguard 11 - Quality of CDR data

Take reasonable steps to ensure CDR data is accurate, up to date and complete having regard to the purpose.

Artefacts an auditor will ask for
  • Data quality checks
  • Correction processes feeding quality
Where this commonly fails
  • No data quality controls
  • Inaccurate data used in decisions
AUCDR-PS-12
Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data

Protect CDR data from misuse, interference, loss and unauthorised access, and destroy or de-identify redundant CDR data.

Artefacts an auditor will ask for
  • Information security controls (Schedule 2)
  • Redundant-data destruction/de-identification records
Where this commonly fails
  • Redundant CDR data retained
  • Security controls not applied to CDR data
AUCDR-PS-13
Privacy Safeguard 13 - Correction of CDR data

Correct CDR data on request or when satisfied it is inaccurate, out of date, incomplete, irrelevant or misleading.

Artefacts an auditor will ask for
  • Correction request process
  • Records of corrections made
Where this commonly fails
  • No correction mechanism
  • Correction requests not actioned
AUCDR-PS-2
Privacy Safeguard 2 - Anonymity and pseudonymity

Give individuals the option of not identifying themselves, or of using a pseudonym, where lawful and practicable.

Artefacts an auditor will ask for
  • Anonymity/pseudonymity options where applicable
  • Assessment of practicability
Where this commonly fails
  • No anonymity option considered
  • Identification required without justification
AUCDR-PS-3
Privacy Safeguard 3 - Seeking to collect CDR data from CDR participants

Only seek to collect CDR data with valid consent and in accordance with the CDR Rules.

Artefacts an auditor will ask for
  • Valid consent records before collection
  • Collection limited to consented scope
Where this commonly fails
  • Collection without valid consent
  • Over-collection beyond consent
AUCDR-PS-4
Privacy Safeguard 4 - Dealing with unsolicited CDR data

Where unsolicited CDR data is received, determine whether it could have been collected and, if not, destroy or de-identify it.

Artefacts an auditor will ask for
  • Process for handling unsolicited CDR data
  • Destruction/de-identification records
Where this commonly fails
  • Unsolicited data retained without assessment
  • No handling procedure
AUCDR-PS-5
Privacy Safeguard 5 - Notifying of the collection of CDR data

Notify the consumer of the collection of CDR data, including via the consumer dashboard and a CDR receipt.

Artefacts an auditor will ask for
  • Collection notifications / CDR receipts
  • Consumer dashboard entries
Where this commonly fails
  • Collection not notified
  • No CDR receipt provided
AUCDR-PS-6
Privacy Safeguard 6 - Use or disclosure of CDR data

Only use or disclose CDR data in accordance with consent and the CDR Rules.

Artefacts an auditor will ask for
  • Use/disclosure tied to consent
  • Logs of use and disclosure
Where this commonly fails
  • Use/disclosure beyond consent
  • No traceability of use
AUCDR-PS-7
Privacy Safeguard 7 - Use or disclosure of CDR data for direct marketing

Do not use or disclose CDR data for direct marketing except as permitted by the CDR Rules.

Artefacts an auditor will ask for
  • Controls preventing unauthorised direct marketing
  • Consent basis for any permitted marketing
Where this commonly fails
  • CDR data used for marketing without basis
  • No opt-out honoured
AUCDR-PS-8
Privacy Safeguard 8 - Overseas disclosure of CDR data

Before disclosing CDR data overseas, take reasonable steps to ensure the overseas recipient complies with the safeguards.

Artefacts an auditor will ask for
  • Overseas disclosure assessment
  • Contractual safeguards with overseas recipients
Where this commonly fails
  • Overseas disclosure without safeguards
  • No assessment of recipient compliance
AUCDR-PS-9
Privacy Safeguard 9 - Adoption or disclosure of government related identifiers

Do not adopt, use or disclose a government related identifier as the individual's own identifier except as permitted.

Artefacts an auditor will ask for
  • Controls on government identifier use
  • Justification where permitted
Where this commonly fails
  • Government identifier used as own identifier
  • No control over identifier handling
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Australia Consumer Data Right - Banking (CDR) framework page.