ISO/IEC 27557:2022 - Organisational Privacy Risk Management
Evidence request list. 41 controls, 41 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Clause 1-3: Introductory Provisions
Defines the scope of security evaluation of QKD under the ISO/IEC 15408 series framework
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
References to ISO/IEC 15408 series, ISO/IEC 19790, and related cryptographic module standards
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Terminology specific to quantum key distribution security evaluation
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Defines scope of guidelines for organizational privacy risk management extended from ISO 31000:2018
- Privacy risk assessment
- Scope statement
- Definitions glossary
- Reference catalog
- Scope ambiguous
- Reference list incomplete
- Definitions inconsistent
- No baseline assessment
References to ISO 31000:2018, ISO/IEC 27005, and ISO/IEC 29100
- Privacy risk assessment
- Scope statement
- Definitions glossary
- Reference catalog
- Scope ambiguous
- Reference list incomplete
- Definitions inconsistent
- No baseline assessment
Privacy risk management terminology including PII, privacy event, and organizational privacy risk
- Privacy risk assessment
- Scope statement
- Definitions glossary
- Reference catalog
- Scope ambiguous
- Reference list incomplete
- Definitions inconsistent
- No baseline assessment
Clause 4: Principles of Privacy Risk Management
ISO 31000:2018 risk management principles applied with privacy-specific guidance
- Privacy risk management framework document
- Privacy risk register with individual impact ratings
- Privacy risk treatment plan
- Leadership commitment statement and minutes
- Monitoring and review reports
- Privacy risks treated separately from enterprise risk register
- No individual impact lens applied to risk scoring
- Leadership commitment is informal, not documented
- Treatment plans lack owners and due dates
Integrating privacy risks into the overall organizational risk management framework
- Privacy risk management framework document
- Privacy risk register with individual impact ratings
- Privacy risk treatment plan
- Leadership commitment statement and minutes
- Monitoring and review reports
- Privacy risks treated separately from enterprise risk register
- No individual impact lens applied to risk scoring
- Leadership commitment is informal, not documented
- Treatment plans lack owners and due dates
Considering adverse privacy impacts on individuals as part of organizational risk assessment
- Privacy risk management framework document
- Privacy risk register with individual impact ratings
- Privacy risk treatment plan
- Leadership commitment statement and minutes
- Monitoring and review reports
- Privacy risks treated separately from enterprise risk register
- No individual impact lens applied to risk scoring
- Leadership commitment is informal, not documented
- Treatment plans lack owners and due dates
Clause 5: Privacy Risk Management Framework
Leadership commitment to integrating privacy risk management into organizational governance
- Privacy risk management framework document
- Privacy risk register with individual impact ratings
- Privacy risk treatment plan
- Leadership commitment statement and minutes
- Monitoring and review reports
- Privacy risks treated separately from enterprise risk register
- No individual impact lens applied to risk scoring
- Leadership commitment is informal, not documented
- Treatment plans lack owners and due dates
Integrating privacy risk management into organizational decision-making and planning
- Privacy risk management framework document
- Privacy risk register with individual impact ratings
- Privacy risk treatment plan
- Leadership commitment statement and minutes
- Monitoring and review reports
- Privacy risks treated separately from enterprise risk register
- No individual impact lens applied to risk scoring
- Leadership commitment is informal, not documented
- Treatment plans lack owners and due dates
Designing the privacy risk management framework including context, scope, and criteria
- Privacy risk management framework document
- Privacy risk register with individual impact ratings
- Privacy risk treatment plan
- Leadership commitment statement and minutes
- Monitoring and review reports
- Privacy risks treated separately from enterprise risk register
- No individual impact lens applied to risk scoring
- Leadership commitment is informal, not documented
- Treatment plans lack owners and due dates
Implementing, evaluating, and improving the privacy risk management framework
- Privacy risk management framework document
- Privacy risk register with individual impact ratings
- Privacy risk treatment plan
- Leadership commitment statement and minutes
- Monitoring and review reports
- Privacy risks treated separately from enterprise risk register
- No individual impact lens applied to risk scoring
- Leadership commitment is informal, not documented
- Treatment plans lack owners and due dates
Clause 6: Privacy Risk Management Process
Communicating and consulting with stakeholders throughout the privacy risk management process
- Privacy risk management framework document
- Privacy risk register with individual impact ratings
- Privacy risk treatment plan
- Leadership commitment statement and minutes
- Monitoring and review reports
- Privacy risks treated separately from enterprise risk register
- No individual impact lens applied to risk scoring
- Leadership commitment is informal, not documented
- Treatment plans lack owners and due dates
Defining scope, context, and risk criteria specifically for privacy risk management
- Privacy risk management framework document
- Privacy risk register with individual impact ratings
- Privacy risk treatment plan
- Leadership commitment statement and minutes
- Monitoring and review reports
- Privacy risks treated separately from enterprise risk register
- No individual impact lens applied to risk scoring
- Leadership commitment is informal, not documented
- Treatment plans lack owners and due dates
Identifying, analysing, and evaluating privacy risks including risks to individuals and the organization
- Privacy risk management framework document
- Privacy risk register with individual impact ratings
- Privacy risk treatment plan
- Leadership commitment statement and minutes
- Monitoring and review reports
- Privacy risks treated separately from enterprise risk register
- No individual impact lens applied to risk scoring
- Leadership commitment is informal, not documented
- Treatment plans lack owners and due dates
Selecting and implementing measures to treat identified privacy risks
- Privacy risk management framework document
- Privacy risk register with individual impact ratings
- Privacy risk treatment plan
- Leadership commitment statement and minutes
- Monitoring and review reports
- Privacy risks treated separately from enterprise risk register
- No individual impact lens applied to risk scoring
- Leadership commitment is informal, not documented
- Treatment plans lack owners and due dates
Monitoring and reviewing privacy risk management activities and outcomes
- Privacy risk management framework document
- Privacy risk register with individual impact ratings
- Privacy risk treatment plan
- Leadership commitment statement and minutes
- Monitoring and review reports
- Privacy risks treated separately from enterprise risk register
- No individual impact lens applied to risk scoring
- Leadership commitment is informal, not documented
- Treatment plans lack owners and due dates
Recording and reporting privacy risk management activities and decisions
- Privacy risk management framework document
- Privacy risk register with individual impact ratings
- Privacy risk treatment plan
- Leadership commitment statement and minutes
- Monitoring and review reports
- Privacy risks treated separately from enterprise risk register
- No individual impact lens applied to risk scoring
- Leadership commitment is informal, not documented
- Treatment plans lack owners and due dates
Clause 7: Privacy-Specific Risk Considerations
Distinguishing information risks from privacy risks, including risks to individuals and organizational impacts
- Privacy risk management framework document
- Privacy risk register with individual impact ratings
- Privacy risk treatment plan
- Leadership commitment statement and minutes
- Monitoring and review reports
- Privacy risks treated separately from enterprise risk register
- No individual impact lens applied to risk scoring
- Leadership commitment is informal, not documented
- Treatment plans lack owners and due dates
Assessing organizational consequences of privacy events that damage the organization
- Privacy risk management framework document
- Privacy risk register with individual impact ratings
- Privacy risk treatment plan
- Leadership commitment statement and minutes
- Monitoring and review reports
- Privacy risks treated separately from enterprise risk register
- No individual impact lens applied to risk scoring
- Leadership commitment is informal, not documented
- Treatment plans lack owners and due dates
Implementing a risk-based privacy program integrated in overall organizational risk management
- Privacy risk management framework document
- Privacy risk register with individual impact ratings
- Privacy risk treatment plan
- Leadership commitment statement and minutes
- Monitoring and review reports
- Privacy risks treated separately from enterprise risk register
- No individual impact lens applied to risk scoring
- Leadership commitment is informal, not documented
- Treatment plans lack owners and due dates
Communication
Communicate privacy risks and treatments to internal and external stakeholders including data subjects where appropriate.
- communication plan
- stakeholder briefing records
- privacy notices reflecting risks
- regulator notifications
- data subject communication absent
- internal comms not segmented by audience
- regulator notification ad hoc
Consult with affected individuals, representatives, or supervisory authorities where required prior to high risk processing.
- consultation logs
- DPIA prior consultation records
- representative body engagement evidence
- feedback incorporation register
- prior consultation skipped for high residual risk
- no feedback loop closure
- consultations performed after deployment
Foundation
Define the scope of organisational privacy risk management including business units, processing activities, and jurisdictions covered.
- privacy risk management scope statement
- processing activity register
- jurisdictional applicability matrix
- exclusions log
- scope limited to one business unit
- no jurisdictional analysis
- scope not refreshed annually
Establish external and internal context including stakeholder expectations, regulatory landscape, and organisational privacy objectives.
- context analysis document
- stakeholder map
- regulatory inventory
- privacy objectives register
- stakeholders not segmented (data subjects vs regulators vs partners)
- regulatory inventory missing emerging laws
- objectives not measurable
Governance
Top management demonstrates commitment to privacy risk management through policy, resourcing, and accountability assignment.
- board approved privacy risk policy
- DPO appointment letter
- privacy risk committee charter
- resource allocation evidence
- DPO not independent of processing decisions
- no board reporting cadence
- resource allocation not documented
Define roles for privacy risk owners, control owners, PII controllers, processors, and accountability boundaries.
- RACI matrix for privacy risks
- controller and processor designations
- role descriptions
- delegation of authority register
- controller and processor relationships undocumented for joint controllers
- no escalation path defined
- role overlap with security team unresolved
Improvement
Identify and implement improvements to the privacy risk management process based on monitoring, reviews, and incidents.
- improvement register
- lessons learned documents
- process change records
- before and after metrics
- improvements identified but not tracked to closure
- lessons not extracted from near misses
- no metric improvement evidence
Maintain documented information for privacy risk management with version control, retention, and access controls.
- document control register
- version history
- retention schedule for risk records
- access control list for sensitive risks
- risk register stored in shared spreadsheet without version control
- no retention defined
- all staff can view sensitive risk details
Monitoring
Monitor privacy risks continuously through KRIs, incident data, regulatory changes, and processing changes.
- KRI dashboard
- incident to risk linkage
- regulatory horizon scan
- change trigger log
- KRIs measure activity not risk movement
- incidents not fed back to risk register
- horizon scan informal
Review privacy risks periodically and on trigger events such as new processing, breaches, or regulatory updates.
- review schedule
- review minutes
- trigger event log
- risk register version history
- annual review only (no trigger driven)
- register versions not preserved
- breach reviews skip register update
Measure effectiveness of the privacy risk management process itself including control performance and process maturity.
- effectiveness metrics report
- maturity assessment
- control testing results
- process audit reports
- process effectiveness conflated with control effectiveness
- maturity self assessed only
- no independent validation
Risk Assessment
Document repeatable methodology for privacy risk identification, analysis, and evaluation distinct from security risk methodology.
- privacy risk methodology document
- likelihood and consequence scales
- risk evaluation criteria
- method validation evidence
- methodology copies security approach without privacy harm dimensions
- consequence scales ignore intangible harms to individuals
- no calibration
Identify privacy risks across PII lifecycle including collection, use, retention, sharing, and disposal.
- risk identification workshops minutes
- data flow diagrams
- threat scenarios catalogue
- PII inventory linked to risks
- risks identified at system level not processing activity level
- secondary use scenarios missed
- deletion phase risks ignored
Analyse identified risks considering harm to individuals, likelihood factors, and existing control effectiveness.
- risk analysis worksheets
- harm severity assessments
- control effectiveness ratings
- uncertainty documentation
- harm assessment only considers financial loss
- vulnerable populations not flagged
- control effectiveness rated without testing
Evaluate risks against acceptance criteria distinguishing risks to individuals from risks to the organisation.
- risk evaluation report
- risk acceptance criteria document
- individual risk view vs organisational risk view
- evaluation sign offs
- only organisational view documented
- acceptance criteria not approved by accountable party
- individual harms aggregated incorrectly
Treatment
Select treatment options including avoidance, modification, sharing, or retention with documented justification.
- treatment option analysis
- selected treatment register
- cost benefit analyses
- alternative considered log
- only modification considered (acceptance and avoidance overlooked)
- transfer to processor recorded without due diligence
- no residual risk recalculation
Select privacy controls aligned with ISO 27701 or equivalent and map to specific risks being treated.
- control selection matrix
- ISO 27701 mapping or SoA
- risk to control traceability
- control owner assignment
- controls selected without risk reference
- SoA exclusions not justified
- control owners not signed off
Document treatment plans with actions, owners, deadlines, resources, and success criteria for each accepted risk.
- treatment plan register
- Gantt or roadmap
- budget allocations
- success criteria definitions
- plans lack deadlines
- no success criteria (only completion check)
- resource gaps not escalated
Document and formally accept residual privacy risks by the appropriate risk owner including individuals impacted.
- residual risk register
- formal acceptance records
- DPO opinion documentation
- review schedule
- acceptance signed by IT not business owner
- no DPO advisory opinion attached
- no review trigger defined
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.