Skip to content

Evidence request lists

ISO/IEC 29134:2023

Evidence request list. 43 controls, 43 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Analysis

ISO29134-6.1
Processing Description

Describe processing systematically including purposes, lawful basis, PII categories, recipients, retention, and transfers.

Artefacts an auditor will ask for
  • systematic processing description
  • data flow diagrams
  • retention schedule extract
  • transfer mechanisms list
Where this commonly fails
  • lawful basis described as legitimate interests without LIA
  • retention generic across PII categories
  • transfers not enumerated
ISO29134-6.2
Necessity and Proportionality Assessment

Assess necessity and proportionality of processing including alternatives considered and rejected.

Artefacts an auditor will ask for
  • necessity analysis
  • proportionality assessment
  • alternatives considered log
  • minimisation outcomes
Where this commonly fails
  • proportionality assumed not assessed
  • no alternatives documented
  • less intrusive options not analysed
ISO29134-6.3
Stakeholder Consultation

Consult with internal stakeholders, PII principals or their representatives, and other relevant parties.

Artefacts an auditor will ask for
  • consultation plan
  • consultation records
  • feedback log
  • incorporation decisions
Where this commonly fails
  • PII principals not consulted (only internal)
  • consultations not documented
  • feedback not addressed in PIA

Clause 1-4: Introduction and Context

27014-1
Scope

Defines the scope of guidance on concepts, objectives, and processes for governance of information security

Artefacts an auditor will ask for
  • Scope statement
  • Concept reference
  • Definitions glossary
  • Governance charter
Where this commonly fails
  • Scope unclear
  • Concepts not adopted
  • Glossary outdated
  • Charter inactive
27014-3
Terms and definitions

Key terms including governance, governing body, information security, and management

Artefacts an auditor will ask for
  • Scope statement
  • Concept reference
  • Definitions glossary
  • Governance charter
Where this commonly fails
  • Scope unclear
  • Concepts not adopted
  • Glossary outdated
  • Charter inactive
27014-4
Concepts

Fundamental concepts of information security governance and its relationship to organizational governance

Artefacts an auditor will ask for
  • Scope statement
  • Concept reference
  • Definitions glossary
  • Governance charter
Where this commonly fails
  • Scope unclear
  • Concepts not adopted
  • Glossary outdated
  • Charter inactive
29134-1
Scope

Guidelines for a process on privacy impact assessments and structure and content of a PIA report

Artefacts an auditor will ask for
  • PIA template
  • DPIA report
  • Privacy risk register
  • Mitigation plan
Where this commonly fails
  • PIA skipped at design
  • DPIA shallow
  • Risk catalogue incomplete
  • Mitigations not tracked
29134-3
Terms and definitions

Privacy impact assessment terminology including PII, privacy risk, and PIA report

Artefacts an auditor will ask for
  • PIA template
  • DPIA report
  • Privacy risk register
  • Mitigation plan
Where this commonly fails
  • PIA skipped at design
  • DPIA shallow
  • Risk catalogue incomplete
  • Mitigations not tracked
29134-4
General overview

General overview of PIA process, its purpose, and relationship to other privacy management activities

Artefacts an auditor will ask for
  • PIA template
  • DPIA report
  • Privacy risk register
  • Mitigation plan
Where this commonly fails
  • PIA skipped at design
  • DPIA shallow
  • Risk catalogue incomplete
  • Mitigations not tracked

Clause 5: PIA Initiation and Scope

29134-5.1
Determining PIA necessity

Criteria and thresholds for determining when a privacy impact assessment is necessary

Artefacts an auditor will ask for
  • Privacy impact assessment report
  • Data flow diagrams and processing description
  • PIA risk register and treatment plan
  • Stakeholder consultation records
  • Residual risk acceptance memo
Where this commonly fails
  • PIAs triggered late in project lifecycle
  • Risk likelihood scoring is subjective and inconsistent
  • Residual risk not formally accepted by accountable owner
  • PIA outputs not refreshed when processing changes
29134-5.2
Defining PIA scope

Defining the scope of the assessment including systems, processes, and data flows to be assessed

Artefacts an auditor will ask for
  • Privacy impact assessment report
  • Data flow diagrams and processing description
  • PIA risk register and treatment plan
  • Stakeholder consultation records
  • Residual risk acceptance memo
Where this commonly fails
  • PIAs triggered late in project lifecycle
  • Risk likelihood scoring is subjective and inconsistent
  • Residual risk not formally accepted by accountable owner
  • PIA outputs not refreshed when processing changes
29134-5.3
Stakeholder identification

Identifying relevant stakeholders including data subjects, controllers, processors, and regulators

Artefacts an auditor will ask for
  • Privacy impact assessment report
  • Data flow diagrams and processing description
  • PIA risk register and treatment plan
  • Stakeholder consultation records
  • Residual risk acceptance memo
Where this commonly fails
  • PIAs triggered late in project lifecycle
  • Risk likelihood scoring is subjective and inconsistent
  • Residual risk not formally accepted by accountable owner
  • PIA outputs not refreshed when processing changes

Clause 6: Data Flow and Processing Analysis

29134-6.1
Information flow identification

Identifying and describing information flows and data processing activities involving PII

Artefacts an auditor will ask for
  • Privacy impact assessment report
  • Data flow diagrams and processing description
  • PIA risk register and treatment plan
  • Stakeholder consultation records
  • Residual risk acceptance memo
Where this commonly fails
  • PIAs triggered late in project lifecycle
  • Risk likelihood scoring is subjective and inconsistent
  • Residual risk not formally accepted by accountable owner
  • PIA outputs not refreshed when processing changes
29134-6.2
PII processing description

Describing the nature, scope, context, and purposes of PII processing activities

Artefacts an auditor will ask for
  • Privacy impact assessment report
  • Data flow diagrams and processing description
  • PIA risk register and treatment plan
  • Stakeholder consultation records
  • Residual risk acceptance memo
Where this commonly fails
  • PIAs triggered late in project lifecycle
  • Risk likelihood scoring is subjective and inconsistent
  • Residual risk not formally accepted by accountable owner
  • PIA outputs not refreshed when processing changes
29134-6.3
Legal basis analysis

Analysing the legal basis and legitimacy of PII processing activities

Artefacts an auditor will ask for
  • Privacy impact assessment report
  • Data flow diagrams and processing description
  • PIA risk register and treatment plan
  • Stakeholder consultation records
  • Residual risk acceptance memo
Where this commonly fails
  • PIAs triggered late in project lifecycle
  • Risk likelihood scoring is subjective and inconsistent
  • Residual risk not formally accepted by accountable owner
  • PIA outputs not refreshed when processing changes

Clause 7: Privacy Risk Assessment

29134-7.1
Risk identification

Identifying potential privacy risks to PII principals arising from the processing activities

Artefacts an auditor will ask for
  • Privacy impact assessment report
  • Data flow diagrams and processing description
  • PIA risk register and treatment plan
  • Stakeholder consultation records
  • Residual risk acceptance memo
Where this commonly fails
  • PIAs triggered late in project lifecycle
  • Risk likelihood scoring is subjective and inconsistent
  • Residual risk not formally accepted by accountable owner
  • PIA outputs not refreshed when processing changes
29134-7.2
Impact assessment

Assessing the potential impact and severity of identified privacy risks on individuals

Artefacts an auditor will ask for
  • Privacy impact assessment report
  • Data flow diagrams and processing description
  • PIA risk register and treatment plan
  • Stakeholder consultation records
  • Residual risk acceptance memo
Where this commonly fails
  • PIAs triggered late in project lifecycle
  • Risk likelihood scoring is subjective and inconsistent
  • Residual risk not formally accepted by accountable owner
  • PIA outputs not refreshed when processing changes
29134-7.3
Likelihood assessment

Assessing the likelihood of identified privacy risks materializing

Artefacts an auditor will ask for
  • Privacy impact assessment report
  • Data flow diagrams and processing description
  • PIA risk register and treatment plan
  • Stakeholder consultation records
  • Residual risk acceptance memo
Where this commonly fails
  • PIAs triggered late in project lifecycle
  • Risk likelihood scoring is subjective and inconsistent
  • Residual risk not formally accepted by accountable owner
  • PIA outputs not refreshed when processing changes
29134-7.4
Risk evaluation

Evaluating identified risks against defined criteria to determine risk levels

Artefacts an auditor will ask for
  • Privacy impact assessment report
  • Data flow diagrams and processing description
  • PIA risk register and treatment plan
  • Stakeholder consultation records
  • Residual risk acceptance memo
Where this commonly fails
  • PIAs triggered late in project lifecycle
  • Risk likelihood scoring is subjective and inconsistent
  • Residual risk not formally accepted by accountable owner
  • PIA outputs not refreshed when processing changes

Clause 8: Privacy Risk Treatment

29134-8.1
Treatment options

Selecting and implementing measures to mitigate, transfer, accept, or avoid identified privacy risks

Artefacts an auditor will ask for
  • Privacy impact assessment report
  • Data flow diagrams and processing description
  • PIA risk register and treatment plan
  • Stakeholder consultation records
  • Residual risk acceptance memo
Where this commonly fails
  • PIAs triggered late in project lifecycle
  • Risk likelihood scoring is subjective and inconsistent
  • Residual risk not formally accepted by accountable owner
  • PIA outputs not refreshed when processing changes
29134-8.2
Control selection

Selecting privacy controls and safeguards appropriate to the identified risk levels

Artefacts an auditor will ask for
  • Privacy impact assessment report
  • Data flow diagrams and processing description
  • PIA risk register and treatment plan
  • Stakeholder consultation records
  • Residual risk acceptance memo
Where this commonly fails
  • PIAs triggered late in project lifecycle
  • Risk likelihood scoring is subjective and inconsistent
  • Residual risk not formally accepted by accountable owner
  • PIA outputs not refreshed when processing changes
29134-8.3
Residual risk assessment

Assessing residual privacy risks after implementation of treatment measures

Artefacts an auditor will ask for
  • Privacy impact assessment report
  • Data flow diagrams and processing description
  • PIA risk register and treatment plan
  • Stakeholder consultation records
  • Residual risk acceptance memo
Where this commonly fails
  • PIAs triggered late in project lifecycle
  • Risk likelihood scoring is subjective and inconsistent
  • Residual risk not formally accepted by accountable owner
  • PIA outputs not refreshed when processing changes

Clause 9: PIA Report

29134-9.1
PIA report structure

Structure and content requirements for the privacy impact assessment report

Artefacts an auditor will ask for
  • Privacy impact assessment report
  • Data flow diagrams and processing description
  • PIA risk register and treatment plan
  • Stakeholder consultation records
  • Residual risk acceptance memo
Where this commonly fails
  • PIAs triggered late in project lifecycle
  • Risk likelihood scoring is subjective and inconsistent
  • Residual risk not formally accepted by accountable owner
  • PIA outputs not refreshed when processing changes
29134-9.2
Report findings and recommendations

Documenting PIA findings, recommendations, and planned remediation actions

Artefacts an auditor will ask for
  • Privacy impact assessment report
  • Data flow diagrams and processing description
  • PIA risk register and treatment plan
  • Stakeholder consultation records
  • Residual risk acceptance memo
Where this commonly fails
  • PIAs triggered late in project lifecycle
  • Risk likelihood scoring is subjective and inconsistent
  • Residual risk not formally accepted by accountable owner
  • PIA outputs not refreshed when processing changes
29134-9.3
PIA review and update

Requirements for reviewing and updating the PIA when processing activities change

Artefacts an auditor will ask for
  • Privacy impact assessment report
  • Data flow diagrams and processing description
  • PIA risk register and treatment plan
  • Stakeholder consultation records
  • Residual risk acceptance memo
Where this commonly fails
  • PIAs triggered late in project lifecycle
  • Risk likelihood scoring is subjective and inconsistent
  • Residual risk not formally accepted by accountable owner
  • PIA outputs not refreshed when processing changes
29134-9.4
Publication and communication

Guidance on publishing PIA reports and communicating results to stakeholders

Artefacts an auditor will ask for
  • Privacy impact assessment report
  • Data flow diagrams and processing description
  • PIA risk register and treatment plan
  • Stakeholder consultation records
  • Residual risk acceptance memo
Where this commonly fails
  • PIAs triggered late in project lifecycle
  • Risk likelihood scoring is subjective and inconsistent
  • Residual risk not formally accepted by accountable owner
  • PIA outputs not refreshed when processing changes

Documentation

ISO29134-9.1
PIA Report Documentation

Produce a PIA report capturing process, findings, risks, treatments, residual risks, and conclusions.

Artefacts an auditor will ask for
  • PIA report following template
  • executive summary
  • appendices with workshops and analyses
  • version control
Where this commonly fails
  • report skips executive summary for non technical readers
  • analyses not retained
  • report not version controlled
ISO29134-9.2
PIA Approval and Sign Off

Obtain formal approval from accountable parties including business owner, DPO, and where required senior management.

Artefacts an auditor will ask for
  • sign off records
  • approval workflow
  • dissenting opinions log
  • escalation evidence
Where this commonly fails
  • DPO sign off treated as approval rather than opinion
  • no record of dissent or conditions
  • approval before treatment commitments
ISO29134-9.3
PIA Publication and Sharing

Share PIA outcomes with stakeholders including, where appropriate, publication of summaries to support transparency.

Artefacts an auditor will ask for
  • sharing decisions document
  • published summaries
  • stakeholder distribution log
  • redaction rationale
Where this commonly fails
  • PIAs treated as confidential by default
  • no summary for PII principals
  • redaction not justified

Implementation

ISO29134-10.1
PIA Implementation Tracking

Track implementation of PIA action plan with status reporting and exception management.

Artefacts an auditor will ask for
  • implementation status reports
  • milestone evidence
  • exception requests and approvals
  • completion confirmations
Where this commonly fails
  • status reporting stops before completion
  • exceptions granted without DPO consultation
  • completion not verified
ISO29134-10.2
PIA Review and Update

Review and update the PIA periodically and on trigger events such as processing changes, new risks, or incidents.

Artefacts an auditor will ask for
  • review schedule
  • trigger event register
  • PIA version history
  • update justification documents
Where this commonly fails
  • reviews skipped after initial PIA
  • minor changes not triggering review
  • no version history retained
ISO29134-10.3
Prior Consultation with Supervisory Authority

Where residual high risk remains, consult with the supervisory authority prior to processing.

Artefacts an auditor will ask for
  • prior consultation submissions
  • regulator responses
  • implementation of regulator advice
  • consultation decision criteria
Where this commonly fails
  • high residual risk processed without consultation
  • regulator advice not implemented
  • decision criteria undocumented

Initiation

ISO29134-5.1
PIA Trigger Identification

Identify processing activities requiring a PIA based on threshold criteria including new technology, large scale processing, or special categories.

Artefacts an auditor will ask for
  • PIA threshold criteria document
  • screening questionnaires
  • triggered PIA register
  • exemption justifications
Where this commonly fails
  • screening only at project gate (not for changes)
  • criteria narrower than GDPR Article 35
  • exemptions without DPO sign off
ISO29134-5.2
PIA Scope Definition

Define PIA scope including processing operations, PII categories, actors, lifecycle phases, and jurisdictions.

Artefacts an auditor will ask for
  • scope statement
  • in scope and out of scope documentation
  • boundary diagrams
  • stakeholder list
Where this commonly fails
  • scope limited to data fields not full lifecycle
  • third party processing excluded
  • stakeholders not identified
ISO29134-5.3
PIA Team Composition

Compose PIA team with privacy, legal, security, business, and technical expertise plus DPO involvement.

Artefacts an auditor will ask for
  • team charter
  • role assignments
  • DPO advisory record
  • skills coverage matrix
Where this commonly fails
  • security expertise absent
  • DPO consulted at end only
  • business owner not engaged

Programme

ISO29134-11.1
PIA Programme Maturity

Establish a PIA programme with templates, training, tooling, and continuous improvement to scale across the organisation.

Artefacts an auditor will ask for
  • PIA programme charter
  • templates and tooling
  • training completion records
  • maturity self assessments
Where this commonly fails
  • PIAs ad hoc per project (no programme)
  • templates inconsistent across business units
  • no maturity tracking

Risk Assessment

ISO29134-7.1
Privacy Risk Identification

Identify privacy risks to PII principals across the processing lifecycle using systematic methods.

Artefacts an auditor will ask for
  • risk identification workshops
  • threat scenarios specific to PII principals
  • risk catalogue
  • feared events list
Where this commonly fails
  • risks framed from organisation view not individual harm
  • feared events not enumerated
  • scenarios miss insider threats
ISO29134-7.2
Likelihood Assessment

Assess likelihood of risks materialising considering threat sources, vulnerabilities, and existing controls.

Artefacts an auditor will ask for
  • likelihood scale
  • threat source analysis
  • vulnerability inventory
  • control coverage assessment
Where this commonly fails
  • likelihood scale only qualitative without descriptors
  • external threat sources omitted
  • control effectiveness assumed
ISO29134-7.3
Severity Assessment

Assess severity of risks to PII principals considering tangible and intangible harms and vulnerability of individuals.

Artefacts an auditor will ask for
  • severity scale with harm types
  • vulnerability factors (minors, employees, patients)
  • harm scenarios
  • severity calibration
Where this commonly fails
  • severity only considers data sensitivity not consequence
  • vulnerable populations not flagged
  • intangible harms (discrimination, distress) ignored
ISO29134-7.4
Risk Evaluation Against Criteria

Evaluate risks against documented criteria distinguishing high risks requiring prior consultation with supervisory authority.

Artefacts an auditor will ask for
  • risk evaluation criteria
  • risk register with ratings
  • high risk determinations
  • supervisory authority consultation triggers
Where this commonly fails
  • criteria not approved by accountable owner
  • high risk threshold inconsistent with regulator guidance
  • consultations not triggered

Treatment

ISO29134-8.1
Risk Treatment Measures

Identify measures to address identified risks including controls, design changes, and process modifications.

Artefacts an auditor will ask for
  • treatment measures register
  • design change specifications
  • control implementations
  • responsibility assignments
Where this commonly fails
  • measures generic (encryption, training)
  • design changes not specific
  • responsibility assignments missing deadlines
ISO29134-8.2
Residual Risk Documentation

Recalculate and document residual risks after planned treatment measures with formal acceptance.

Artefacts an auditor will ask for
  • residual risk register
  • before and after risk ratings
  • acceptance records
  • DPO opinion
Where this commonly fails
  • residual ratings assumed equal to inherent minus 1
  • acceptance signer lacks authority
  • DPO opinion not solicited
ISO29134-8.3
Action Plan

Document an action plan for treatment measures with owners, deadlines, dependencies, and success indicators.

Artefacts an auditor will ask for
  • action plan with owners and dates
  • dependency map
  • success indicators
  • tracking dashboard
Where this commonly fails
  • plans lack success indicators
  • dependencies not mapped
  • no tracking beyond initial assignment
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.