Skip to content

Evidence request lists

South Africa Promotion of Access to Information Act (PAIA)

Evidence request list. 23 controls, 23 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Appeals and Personal Information Requests

PAIA-INT-07
Internal appeal mechanism

Although internal appeal applies primarily to public bodies, private bodies shall provide a clear process for the requester to escalate refusals to the Information Regulator and ultimately to court within prescribed timeframes.

Artefacts an auditor will ask for
  • Escalation pathway included in decision letter
  • Contact details for Information Regulator
  • Court application timeframes stated
  • Complaints register with status
  • Resolution tracking dashboard
Where this commonly fails
  • Refusal letters omit escalation rights
  • Information Regulator contact details outdated
  • 180 day judicial review window not communicated
PAIA-PRV-11
Personal information requests by data subjects

Requests by individuals for access to their own personal information held by a private body shall be processed under PAIA in conjunction with POPIA section 23, with fees waived for personal information.

Artefacts an auditor will ask for
  • Identity verification procedure
  • Personal information request workflow
  • Fee waiver application to data subject requests
  • Coordination with POPIA Information Officer function
  • Records of personal information disclosed
Where this commonly fails
  • Fees charged in error for own personal information
  • Identity verification weak risking impersonation
  • PAIA and POPIA timelines confused

Cooperation

SAPAIA-4
Information Regulator Cooperation and Appeals

Per PAIA: Information Regulator cooperation + appeals + internal appeal + court review.

Artefacts an auditor will ask for
  • PAIA evidence for SAPAIA-4
Where this commonly fails
  • manual + 30-day response partial

Exemptions

SAPAIA-3
Exemptions, Grounds for Refusal

Per PAIA Chapter 4: exemptions including third-party information + national security + commercial confidentiality + override in public interest.

Artefacts an auditor will ask for
  • PAIA evidence for SAPAIA-3
Where this commonly fails
  • manual + 30-day response partial

Grounds for Refusal and Third Parties

PAIA-3P-06
Third party notification and intervention

Where a request relates to a record containing third party information, the Information Officer shall notify the third party within 21 days and allow representations within a further 21 days before deciding the request.

Artefacts an auditor will ask for
  • Third party notification template
  • Notification dispatch log with delivery proof
  • Third party representations register
  • Decision rationale incorporating third party views
  • Internal review or judicial review records where intervention escalated
Where this commonly fails
  • Third parties not identified until late in process
  • Notification periods truncated
  • Decision sent to requester before third party representation deadline
PAIA-COM-12
Mandatory disclosure where public interest overrides exemption

Access shall be granted to records that would otherwise be refused if the disclosure reveals evidence of substantial contravention of law or imminent and serious public safety or environmental risk, and the public interest outweighs the harm.

Artefacts an auditor will ask for
  • Public interest test template
  • Legal opinion files where override considered
  • Decision records applying section 70
  • Whistleblower handling interface
  • Training on override criteria
Where this commonly fails
  • Override never invoked despite plausible cases
  • Test conducted but not documented
  • Environmental risk threshold not defined
PAIA-GRD-05
Mandatory and discretionary grounds for refusal

Access shall be refused on mandatory grounds including third party personal information, commercial information of third parties, and protection of safety of individuals and property, and may be refused on discretionary grounds including legal privilege and operations of the body.

Artefacts an auditor will ask for
  • Refusal decision log mapped to specific PAIA sections
  • Public interest override analysis where relevant
  • Severability assessment for partial access
  • Third party consultation records
  • Training records on grounds for refusal
Where this commonly fails
  • Blanket refusals without section citation
  • Severability not considered
  • Third party notification omitted
  • Public interest override not assessed

Information Officer, Manual and Training

PAIA-IO-01
Designation of Information Officer

Every private body shall have an Information Officer who is the head of the body, with authority to delegate functions to Deputy Information Officers, and whose details are registered with the Information Regulator.

Artefacts an auditor will ask for
  • Information Officer designation letter
  • Deputy Information Officer appointments
  • Registration confirmation from Information Regulator
  • Internal authority delegation matrix
  • Contact details published on body website
Where this commonly fails
  • Information Officer role conflated with POPIA role without dual mandate clarity
  • Deputies appointed without formal delegation
  • Registrar details not updated after personnel changes
PAIA-MAN-02
PAIA manual under section 51

Every private body shall compile a manual containing prescribed information including contact details, description of records held by subject and category, request procedures, and categories of records automatically available, subject to exemptions granted by the Minister.

Artefacts an auditor will ask for
  • Current PAIA manual in three official languages or accessible format
  • Records categorisation schedule
  • Manual published on website and available at principal office
  • Submission to Information Regulator
  • Manual review and update log
Where this commonly fails
  • Manual not updated after organisational changes
  • Records categories generic and unhelpful
  • Languages required by Regulator not provided
  • No accessible version for persons with disabilities
PAIA-TRG-09
Staff training on PAIA

All staff handling records and requests shall receive training on PAIA obligations, grounds for refusal, record categorisation, and procedural timelines, with refresher training when material changes occur.

Artefacts an auditor will ask for
  • Annual training plan including PAIA
  • Attendance registers per session
  • Training materials version controlled
  • Competency assessment results
  • Information Officer specialised training certificates
Where this commonly fails
  • Training combined with POPIA without distinct PAIA content
  • No refresher after Regulator guidance updates
  • New starters not trained within first 90 days

Manuals

SAPAIA-1
PAIA Manuals for Public and Private Bodies

Per SA Promotion of Access to Information Act: PAIA Manual for Public Bodies (Section 14) + PAIA Manual for Private Bodies (Section 51) + voluntary disclosure.

Artefacts an auditor will ask for
  • PAIA evidence for SAPAIA-1
Where this commonly fails
  • manual + 30-day response partial

Objects of the Act and Guides

PAIA-1.1
Objects of Act (Section 9)

Give effect to the constitutional right of access to information held by the State or private bodies

Artefacts an auditor will ask for
  • Statutory mapping document linking definitions to internal terms
  • Scope statement signed by accountable owner
  • Glossary version control with effective dates
  • AI system inventory with risk classification
  • Model evaluation reports including bias and safety testing
  • AI ethics committee review records
Where this commonly fails
  • AI inventory missing shadow deployments by business units
  • Bias and safety testing not performed at required cadence
  • Documentation exists but lacks evidence of periodic refresh
PAIA-1.2
Guide on How to Use Act (Section 10)

Human Rights Commission must compile a guide on how to exercise rights under PAIA

Artefacts an auditor will ask for
  • AI system inventory with risk classification
  • Model evaluation reports including bias and safety testing
  • AI ethics committee review records
Where this commonly fails
  • AI inventory missing shadow deployments by business units
  • Bias and safety testing not performed at required cadence
  • Documentation exists but lacks evidence of periodic refresh

Records Management and Proactive Disclosure

PAIA-EXT-17
Voluntary disclosure and proactive publication

Private bodies are encouraged to voluntarily publish categories of records that are automatically available without a formal request, as listed in their PAIA manual, supporting transparency and reducing request volumes.

Artefacts an auditor will ask for
  • List of automatically available record categories
  • Website publication of records
  • Monitoring of access statistics
  • Update cadence documented
  • Format accessibility check
Where this commonly fails
  • Published list never refreshed
  • Links broken or behind authentication
  • No accessibility testing
PAIA-REC-10
Records management

Records subject to PAIA shall be managed throughout their lifecycle with retention schedules, search and retrieval capability, and protection against unauthorised alteration or destruction during the request period.

Artefacts an auditor will ask for
  • Records retention schedule
  • Records management policy
  • Litigation and request hold procedure
  • Search and indexing tooling documentation
  • Destruction certificates with PAIA hold checks
Where this commonly fails
  • No hold mechanism for active PAIA requests
  • Email and instant message records not searchable
  • Backup tapes excluded from search scope

Reporting and Self Assessment

PAIA-AUD-16
Information Officer audit and self assessment

Information Officers shall periodically assess compliance with PAIA obligations and maintain evidence of corrective actions taken on identified gaps, with results reported to executive management.

Artefacts an auditor will ask for
  • Annual PAIA self assessment workbook
  • Corrective action register
  • Executive committee minutes acknowledging report
  • Internal audit reports including PAIA scope
  • Benchmarking against Regulator guidance
Where this commonly fails
  • Self assessment treated as form filling
  • Corrective actions not tracked to closure
  • PAIA excluded from internal audit universe
PAIA-RPT-08
Annual report to Information Regulator

Information Officers of private bodies shall submit annual reports to the Information Regulator detailing the number of requests received, granted, refused, and the grounds for refusal, within the prescribed reporting period.

Artefacts an auditor will ask for
  • Annual section 32 report submitted
  • Confirmation of submission from Regulator
  • Statistical reconciliation to internal request log
  • Board or executive sign-off on report
  • Methodology note on counting requests
Where this commonly fails
  • Reports not aligned to Regulator template
  • Late submissions
  • Statistics not reconciling to internal logs
  • Refusal grounds aggregated rather than per request

Request Handling, Fees and Forms

PAIA-FEE-04
Fees for access

A request fee may be charged for processing the request and an access fee for reproduction and search time, with prescribed rates set by the Minister, and indigent persons exempted from the request fee on production of acceptable proof.

Artefacts an auditor will ask for
  • Current fee schedule per gazetted rates
  • Fee calculation worksheets per request
  • Receipts issued to requesters
  • Indigent waiver decisions with supporting documentation
  • Annual fee reconciliation to revenue
Where this commonly fails
  • Outdated fee amounts charged
  • Fees not waived for personal information requests
  • Indigent test inconsistently applied
PAIA-FRM-13
Forms and prescribed format compliance

Requests, decisions, fee notifications, and third party notifications shall use the prescribed forms set out in the PAIA Regulations, with assistance provided to requesters who cannot complete the forms.

Artefacts an auditor will ask for
  • Current version of Forms 2, 3, 4 and others as applicable
  • Assistance procedure for requesters
  • Forms in accessible formats including braille on request
  • Records of assistance provided
  • Translation arrangements where requester is not proficient
Where this commonly fails
  • Outdated 2002 forms still in use
  • No mechanism for telephonic or in-person assistance
  • Forms only available in English
PAIA-FRV-15
Frivolous or vexatious requests

A request may be refused if it is manifestly frivolous or vexatious, or the work involved would substantially and unreasonably divert the resources of the body, with the burden of justifying the refusal on the body.

Artefacts an auditor will ask for
  • Vexatious request test documented per case
  • Estimated effort calculation
  • Senior review of vexatious determinations
  • Pattern analysis across requests by same requester
  • Notification with right to escalate
Where this commonly fails
  • Vexatious flag applied without effort estimation
  • No engagement with requester to narrow scope
  • No senior sign-off on refusal
PAIA-REQ-03
Request handling procedure

Requesters shall submit requests on prescribed Form 2, and the private body shall acknowledge, decide within 30 days extendable by a further 30 days for good cause, and notify the requester in writing of the decision with reasons.

Artefacts an auditor will ask for
  • Standard operating procedure for request intake
  • Request log with date received, decided, notified
  • Acknowledgement letter template
  • Decision letter template with grounds for refusal
  • Extension notification template
Where this commonly fails
  • Form 2 not accepted in electronic submission
  • Extension reasons generic
  • Decisions communicated verbally only
  • 30 day clock started incorrectly
PAIA-SEV-14
Severability and partial access

If a record contains both information that may be refused and information to which access could be granted, the body shall disclose the latter portion after severing the protected information where reasonably possible.

Artefacts an auditor will ask for
  • Redaction procedure with technical controls
  • Severed copy delivery records
  • Reasoning for redactions per page or paragraph
  • Reviewer second pair of eyes log
  • Tooling that prevents reversal of redactions
Where this commonly fails
  • Black box redactions reversible in PDF
  • Whole document refused where partial access feasible
  • Reviewer not independent of decision maker

Right of Access

SAPAIA-2
Right of Access and Request Processes

Per PAIA: Right of Access to Records (Section 11) + Form of Request (Section 18) + 30-day response + Information Officer processing.

Artefacts an auditor will ask for
  • PAIA evidence for SAPAIA-2
Where this commonly fails
  • manual + 30-day response partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the South Africa Promotion of Access to Information Act (PAIA) framework page.