Skip to content

Evidence request lists

Consumer Data Right Rules 2020 (selected operational obligations)

Evidence request list. 9 controls, 9 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Selected CDR Rules obligations

AUCDR-OB-1
Accreditation as an accredited data recipient

Obtain and maintain accreditation, meeting the fit-and-proper, information security and other accreditation criteria before collecting CDR data.

Artefacts an auditor will ask for
  • Accreditation status and number
  • Evidence accreditation criteria are maintained
Where this commonly fails
  • Collecting CDR data without accreditation
  • Accreditation criteria lapsed
AUCDR-OB-2
Consent requirements

Obtain valid, informed consent for collection, use and disclosure, give the consumer the recipient's name and accreditation number, allow withdrawal at any time, and provide a CDR receipt.

Artefacts an auditor will ask for
  • Consent flow meeting CDR Rules Part 4
  • CDR receipts issued
  • Withdrawal mechanism
Where this commonly fails
  • Consent not informed or granular
  • No CDR receipt
  • No easy withdrawal
AUCDR-OB-3
Data minimisation

Only collect and use the CDR data required to provide the requested product or service.

Artefacts an auditor will ask for
  • Mapping of collected data to product/service need
  • Evidence of minimisation in consent design
Where this commonly fails
  • Collecting more data than needed
  • Use beyond the stated purpose
AUCDR-OB-4
CDR policy publication

Maintain a CDR policy that consumers can easily understand and access, covering how data is managed and how to make an enquiry or complaint.

Artefacts an auditor will ask for
  • Published, accessible CDR policy
  • Required content per OAIC guide
Where this commonly fails
  • No CDR policy
  • Policy hard to access or incomplete
AUCDR-OB-5
Deletion or de-identification of redundant data

Inform consumers of their right to have redundant data deleted and delete or de-identify redundant CDR data accordingly.

Artefacts an auditor will ask for
  • Deletion/de-identification on request
  • Notice of deletion right
  • Records of deletions
Where this commonly fails
  • Redundant data retained
  • Deletion right not communicated
AUCDR-OB-6
Records of CDR data

Maintain the records required by CDR Rule 9.3(2), including consents, withdrawals, complaints, deletions, use of data, de-identification, information security records, terms and conditions, and OSP/sponsor/representative arrangements.

Artefacts an auditor will ask for
  • Record set per Rule 9.3(2)
  • Consent and complaint records
  • Information security records
Where this commonly fails
  • Required records not kept
  • Incomplete consent/complaint records
AUCDR-OB-7
Reporting to ACCC and OAIC

Submit reports twice a year to the ACCC and OAIC (per CDR Rule 9.4) and provide a confirmation statement and verification report.

Artefacts an auditor will ask for
  • Bi-annual ACCC/OAIC reports
  • Confirmation statement and verification report
Where this commonly fails
  • Reports not submitted
  • Confirmation/verification report missing
AUCDR-OB-8
Complaints handling

Maintain processes to receive and handle CDR consumer complaints and record complaint data.

Artefacts an auditor will ask for
  • Complaints handling procedure
  • Complaint records and outcomes
Where this commonly fails
  • No complaints process
  • Complaints not recorded
AUCDR-OB-9
Outsourced service provider and representative arrangements

Govern CDR outsourced service provider (OSP), sponsor, affiliate and CDR representative arrangements, including contractual controls and oversight.

Artefacts an auditor will ask for
  • OSP/representative agreements with CDR controls
  • Oversight of arrangements
  • Records of arrangements
Where this commonly fails
  • OSP arrangements ungoverned
  • No contractual CDR controls
  • No oversight of representatives
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.