Skip to content

Evidence request lists

ISO/IEC 27557:2022 - Organisational Privacy Risk Management

Evidence request list. 41 controls, 41 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Clause 1-3: Introductory Provisions

23837-1.1
Scope

Defines the scope of security evaluation of QKD under the ISO/IEC 15408 series framework

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates
23837-1.2
Normative references

References to ISO/IEC 15408 series, ISO/IEC 19790, and related cryptographic module standards

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates
23837-1.3
Terms and definitions

Terminology specific to quantum key distribution security evaluation

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates
27557-1
Scope

Defines scope of guidelines for organizational privacy risk management extended from ISO 31000:2018

Artefacts an auditor will ask for
  • Privacy risk assessment
  • Scope statement
  • Definitions glossary
  • Reference catalog
Where this commonly fails
  • Scope ambiguous
  • Reference list incomplete
  • Definitions inconsistent
  • No baseline assessment
27557-2
Normative references

References to ISO 31000:2018, ISO/IEC 27005, and ISO/IEC 29100

Artefacts an auditor will ask for
  • Privacy risk assessment
  • Scope statement
  • Definitions glossary
  • Reference catalog
Where this commonly fails
  • Scope ambiguous
  • Reference list incomplete
  • Definitions inconsistent
  • No baseline assessment
27557-3
Terms and definitions

Privacy risk management terminology including PII, privacy event, and organizational privacy risk

Artefacts an auditor will ask for
  • Privacy risk assessment
  • Scope statement
  • Definitions glossary
  • Reference catalog
Where this commonly fails
  • Scope ambiguous
  • Reference list incomplete
  • Definitions inconsistent
  • No baseline assessment

Clause 4: Principles of Privacy Risk Management

27557-4.1
General principles

ISO 31000:2018 risk management principles applied with privacy-specific guidance

Artefacts an auditor will ask for
  • Privacy risk management framework document
  • Privacy risk register with individual impact ratings
  • Privacy risk treatment plan
  • Leadership commitment statement and minutes
  • Monitoring and review reports
Where this commonly fails
  • Privacy risks treated separately from enterprise risk register
  • No individual impact lens applied to risk scoring
  • Leadership commitment is informal, not documented
  • Treatment plans lack owners and due dates
27557-4.2
Privacy risk integration

Integrating privacy risks into the overall organizational risk management framework

Artefacts an auditor will ask for
  • Privacy risk management framework document
  • Privacy risk register with individual impact ratings
  • Privacy risk treatment plan
  • Leadership commitment statement and minutes
  • Monitoring and review reports
Where this commonly fails
  • Privacy risks treated separately from enterprise risk register
  • No individual impact lens applied to risk scoring
  • Leadership commitment is informal, not documented
  • Treatment plans lack owners and due dates
27557-4.3
Individual impact consideration

Considering adverse privacy impacts on individuals as part of organizational risk assessment

Artefacts an auditor will ask for
  • Privacy risk management framework document
  • Privacy risk register with individual impact ratings
  • Privacy risk treatment plan
  • Leadership commitment statement and minutes
  • Monitoring and review reports
Where this commonly fails
  • Privacy risks treated separately from enterprise risk register
  • No individual impact lens applied to risk scoring
  • Leadership commitment is informal, not documented
  • Treatment plans lack owners and due dates

Clause 5: Privacy Risk Management Framework

27557-5.1
Leadership and commitment

Leadership commitment to integrating privacy risk management into organizational governance

Artefacts an auditor will ask for
  • Privacy risk management framework document
  • Privacy risk register with individual impact ratings
  • Privacy risk treatment plan
  • Leadership commitment statement and minutes
  • Monitoring and review reports
Where this commonly fails
  • Privacy risks treated separately from enterprise risk register
  • No individual impact lens applied to risk scoring
  • Leadership commitment is informal, not documented
  • Treatment plans lack owners and due dates
27557-5.2
Integration with organizational processes

Integrating privacy risk management into organizational decision-making and planning

Artefacts an auditor will ask for
  • Privacy risk management framework document
  • Privacy risk register with individual impact ratings
  • Privacy risk treatment plan
  • Leadership commitment statement and minutes
  • Monitoring and review reports
Where this commonly fails
  • Privacy risks treated separately from enterprise risk register
  • No individual impact lens applied to risk scoring
  • Leadership commitment is informal, not documented
  • Treatment plans lack owners and due dates
27557-5.3
Design of framework

Designing the privacy risk management framework including context, scope, and criteria

Artefacts an auditor will ask for
  • Privacy risk management framework document
  • Privacy risk register with individual impact ratings
  • Privacy risk treatment plan
  • Leadership commitment statement and minutes
  • Monitoring and review reports
Where this commonly fails
  • Privacy risks treated separately from enterprise risk register
  • No individual impact lens applied to risk scoring
  • Leadership commitment is informal, not documented
  • Treatment plans lack owners and due dates
27557-5.4
Implementation and evaluation

Implementing, evaluating, and improving the privacy risk management framework

Artefacts an auditor will ask for
  • Privacy risk management framework document
  • Privacy risk register with individual impact ratings
  • Privacy risk treatment plan
  • Leadership commitment statement and minutes
  • Monitoring and review reports
Where this commonly fails
  • Privacy risks treated separately from enterprise risk register
  • No individual impact lens applied to risk scoring
  • Leadership commitment is informal, not documented
  • Treatment plans lack owners and due dates

Clause 6: Privacy Risk Management Process

27557-6.1
Communication and consultation

Communicating and consulting with stakeholders throughout the privacy risk management process

Artefacts an auditor will ask for
  • Privacy risk management framework document
  • Privacy risk register with individual impact ratings
  • Privacy risk treatment plan
  • Leadership commitment statement and minutes
  • Monitoring and review reports
Where this commonly fails
  • Privacy risks treated separately from enterprise risk register
  • No individual impact lens applied to risk scoring
  • Leadership commitment is informal, not documented
  • Treatment plans lack owners and due dates
27557-6.2
Scope, context, and criteria for privacy

Defining scope, context, and risk criteria specifically for privacy risk management

Artefacts an auditor will ask for
  • Privacy risk management framework document
  • Privacy risk register with individual impact ratings
  • Privacy risk treatment plan
  • Leadership commitment statement and minutes
  • Monitoring and review reports
Where this commonly fails
  • Privacy risks treated separately from enterprise risk register
  • No individual impact lens applied to risk scoring
  • Leadership commitment is informal, not documented
  • Treatment plans lack owners and due dates
27557-6.3
Privacy risk assessment

Identifying, analysing, and evaluating privacy risks including risks to individuals and the organization

Artefacts an auditor will ask for
  • Privacy risk management framework document
  • Privacy risk register with individual impact ratings
  • Privacy risk treatment plan
  • Leadership commitment statement and minutes
  • Monitoring and review reports
Where this commonly fails
  • Privacy risks treated separately from enterprise risk register
  • No individual impact lens applied to risk scoring
  • Leadership commitment is informal, not documented
  • Treatment plans lack owners and due dates
27557-6.4
Privacy risk treatment

Selecting and implementing measures to treat identified privacy risks

Artefacts an auditor will ask for
  • Privacy risk management framework document
  • Privacy risk register with individual impact ratings
  • Privacy risk treatment plan
  • Leadership commitment statement and minutes
  • Monitoring and review reports
Where this commonly fails
  • Privacy risks treated separately from enterprise risk register
  • No individual impact lens applied to risk scoring
  • Leadership commitment is informal, not documented
  • Treatment plans lack owners and due dates
27557-6.5
Monitoring and review

Monitoring and reviewing privacy risk management activities and outcomes

Artefacts an auditor will ask for
  • Privacy risk management framework document
  • Privacy risk register with individual impact ratings
  • Privacy risk treatment plan
  • Leadership commitment statement and minutes
  • Monitoring and review reports
Where this commonly fails
  • Privacy risks treated separately from enterprise risk register
  • No individual impact lens applied to risk scoring
  • Leadership commitment is informal, not documented
  • Treatment plans lack owners and due dates
27557-6.6
Recording and reporting

Recording and reporting privacy risk management activities and decisions

Artefacts an auditor will ask for
  • Privacy risk management framework document
  • Privacy risk register with individual impact ratings
  • Privacy risk treatment plan
  • Leadership commitment statement and minutes
  • Monitoring and review reports
Where this commonly fails
  • Privacy risks treated separately from enterprise risk register
  • No individual impact lens applied to risk scoring
  • Leadership commitment is informal, not documented
  • Treatment plans lack owners and due dates

Clause 7: Privacy-Specific Risk Considerations

27557-7.1
Types of privacy risk

Distinguishing information risks from privacy risks, including risks to individuals and organizational impacts

Artefacts an auditor will ask for
  • Privacy risk management framework document
  • Privacy risk register with individual impact ratings
  • Privacy risk treatment plan
  • Leadership commitment statement and minutes
  • Monitoring and review reports
Where this commonly fails
  • Privacy risks treated separately from enterprise risk register
  • No individual impact lens applied to risk scoring
  • Leadership commitment is informal, not documented
  • Treatment plans lack owners and due dates
27557-7.2
Organizational consequences of privacy events

Assessing organizational consequences of privacy events that damage the organization

Artefacts an auditor will ask for
  • Privacy risk management framework document
  • Privacy risk register with individual impact ratings
  • Privacy risk treatment plan
  • Leadership commitment statement and minutes
  • Monitoring and review reports
Where this commonly fails
  • Privacy risks treated separately from enterprise risk register
  • No individual impact lens applied to risk scoring
  • Leadership commitment is informal, not documented
  • Treatment plans lack owners and due dates
27557-7.3
Risk-based privacy program implementation

Implementing a risk-based privacy program integrated in overall organizational risk management

Artefacts an auditor will ask for
  • Privacy risk management framework document
  • Privacy risk register with individual impact ratings
  • Privacy risk treatment plan
  • Leadership commitment statement and minutes
  • Monitoring and review reports
Where this commonly fails
  • Privacy risks treated separately from enterprise risk register
  • No individual impact lens applied to risk scoring
  • Leadership commitment is informal, not documented
  • Treatment plans lack owners and due dates

Communication

ISO27557-8.1
Privacy Risk Communication

Communicate privacy risks and treatments to internal and external stakeholders including data subjects where appropriate.

Artefacts an auditor will ask for
  • communication plan
  • stakeholder briefing records
  • privacy notices reflecting risks
  • regulator notifications
Where this commonly fails
  • data subject communication absent
  • internal comms not segmented by audience
  • regulator notification ad hoc
ISO27557-8.2
Consultation with Affected Parties

Consult with affected individuals, representatives, or supervisory authorities where required prior to high risk processing.

Artefacts an auditor will ask for
  • consultation logs
  • DPIA prior consultation records
  • representative body engagement evidence
  • feedback incorporation register
Where this commonly fails
  • prior consultation skipped for high residual risk
  • no feedback loop closure
  • consultations performed after deployment

Foundation

ISO27557-4.1
Privacy Risk Management Scope

Define the scope of organisational privacy risk management including business units, processing activities, and jurisdictions covered.

Artefacts an auditor will ask for
  • privacy risk management scope statement
  • processing activity register
  • jurisdictional applicability matrix
  • exclusions log
Where this commonly fails
  • scope limited to one business unit
  • no jurisdictional analysis
  • scope not refreshed annually
ISO27557-4.2
Privacy Context Establishment

Establish external and internal context including stakeholder expectations, regulatory landscape, and organisational privacy objectives.

Artefacts an auditor will ask for
  • context analysis document
  • stakeholder map
  • regulatory inventory
  • privacy objectives register
Where this commonly fails
  • stakeholders not segmented (data subjects vs regulators vs partners)
  • regulatory inventory missing emerging laws
  • objectives not measurable

Governance

ISO27557-5.1
Privacy Risk Management Leadership

Top management demonstrates commitment to privacy risk management through policy, resourcing, and accountability assignment.

Artefacts an auditor will ask for
  • board approved privacy risk policy
  • DPO appointment letter
  • privacy risk committee charter
  • resource allocation evidence
Where this commonly fails
  • DPO not independent of processing decisions
  • no board reporting cadence
  • resource allocation not documented
ISO27557-5.2
Privacy Risk Roles and Responsibilities

Define roles for privacy risk owners, control owners, PII controllers, processors, and accountability boundaries.

Artefacts an auditor will ask for
  • RACI matrix for privacy risks
  • controller and processor designations
  • role descriptions
  • delegation of authority register
Where this commonly fails
  • controller and processor relationships undocumented for joint controllers
  • no escalation path defined
  • role overlap with security team unresolved

Improvement

ISO27557-10.1
Continual Improvement

Identify and implement improvements to the privacy risk management process based on monitoring, reviews, and incidents.

Artefacts an auditor will ask for
  • improvement register
  • lessons learned documents
  • process change records
  • before and after metrics
Where this commonly fails
  • improvements identified but not tracked to closure
  • lessons not extracted from near misses
  • no metric improvement evidence
ISO27557-10.2
Documentation Management

Maintain documented information for privacy risk management with version control, retention, and access controls.

Artefacts an auditor will ask for
  • document control register
  • version history
  • retention schedule for risk records
  • access control list for sensitive risks
Where this commonly fails
  • risk register stored in shared spreadsheet without version control
  • no retention defined
  • all staff can view sensitive risk details

Monitoring

ISO27557-9.1
Privacy Risk Monitoring

Monitor privacy risks continuously through KRIs, incident data, regulatory changes, and processing changes.

Artefacts an auditor will ask for
  • KRI dashboard
  • incident to risk linkage
  • regulatory horizon scan
  • change trigger log
Where this commonly fails
  • KRIs measure activity not risk movement
  • incidents not fed back to risk register
  • horizon scan informal
ISO27557-9.2
Privacy Risk Review

Review privacy risks periodically and on trigger events such as new processing, breaches, or regulatory updates.

Artefacts an auditor will ask for
  • review schedule
  • review minutes
  • trigger event log
  • risk register version history
Where this commonly fails
  • annual review only (no trigger driven)
  • register versions not preserved
  • breach reviews skip register update
ISO27557-9.3
Effectiveness Measurement

Measure effectiveness of the privacy risk management process itself including control performance and process maturity.

Artefacts an auditor will ask for
  • effectiveness metrics report
  • maturity assessment
  • control testing results
  • process audit reports
Where this commonly fails
  • process effectiveness conflated with control effectiveness
  • maturity self assessed only
  • no independent validation

Risk Assessment

ISO27557-6.1
Privacy Risk Assessment Methodology

Document repeatable methodology for privacy risk identification, analysis, and evaluation distinct from security risk methodology.

Artefacts an auditor will ask for
  • privacy risk methodology document
  • likelihood and consequence scales
  • risk evaluation criteria
  • method validation evidence
Where this commonly fails
  • methodology copies security approach without privacy harm dimensions
  • consequence scales ignore intangible harms to individuals
  • no calibration
ISO27557-6.2
Privacy Risk Identification

Identify privacy risks across PII lifecycle including collection, use, retention, sharing, and disposal.

Artefacts an auditor will ask for
  • risk identification workshops minutes
  • data flow diagrams
  • threat scenarios catalogue
  • PII inventory linked to risks
Where this commonly fails
  • risks identified at system level not processing activity level
  • secondary use scenarios missed
  • deletion phase risks ignored
ISO27557-6.3
Privacy Risk Analysis

Analyse identified risks considering harm to individuals, likelihood factors, and existing control effectiveness.

Artefacts an auditor will ask for
  • risk analysis worksheets
  • harm severity assessments
  • control effectiveness ratings
  • uncertainty documentation
Where this commonly fails
  • harm assessment only considers financial loss
  • vulnerable populations not flagged
  • control effectiveness rated without testing
ISO27557-6.4
Privacy Risk Evaluation

Evaluate risks against acceptance criteria distinguishing risks to individuals from risks to the organisation.

Artefacts an auditor will ask for
  • risk evaluation report
  • risk acceptance criteria document
  • individual risk view vs organisational risk view
  • evaluation sign offs
Where this commonly fails
  • only organisational view documented
  • acceptance criteria not approved by accountable party
  • individual harms aggregated incorrectly

Treatment

ISO27557-7.1
Privacy Risk Treatment Options

Select treatment options including avoidance, modification, sharing, or retention with documented justification.

Artefacts an auditor will ask for
  • treatment option analysis
  • selected treatment register
  • cost benefit analyses
  • alternative considered log
Where this commonly fails
  • only modification considered (acceptance and avoidance overlooked)
  • transfer to processor recorded without due diligence
  • no residual risk recalculation
ISO27557-7.2
Privacy Control Selection

Select privacy controls aligned with ISO 27701 or equivalent and map to specific risks being treated.

Artefacts an auditor will ask for
  • control selection matrix
  • ISO 27701 mapping or SoA
  • risk to control traceability
  • control owner assignment
Where this commonly fails
  • controls selected without risk reference
  • SoA exclusions not justified
  • control owners not signed off
ISO27557-7.3
Treatment Plan Documentation

Document treatment plans with actions, owners, deadlines, resources, and success criteria for each accepted risk.

Artefacts an auditor will ask for
  • treatment plan register
  • Gantt or roadmap
  • budget allocations
  • success criteria definitions
Where this commonly fails
  • plans lack deadlines
  • no success criteria (only completion check)
  • resource gaps not escalated
ISO27557-7.4
Residual Privacy Risk Acceptance

Document and formally accept residual privacy risks by the appropriate risk owner including individuals impacted.

Artefacts an auditor will ask for
  • residual risk register
  • formal acceptance records
  • DPO opinion documentation
  • review schedule
Where this commonly fails
  • acceptance signed by IT not business owner
  • no DPO advisory opinion attached
  • no review trigger defined
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.