Skip to content

Evidence request lists

South Korea Credit Information Act

Evidence request list. 25 controls, 25 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Consent

KRCRED-2
Lawful Basis and Consent for Credit Information

Per CIA: lawful basis + consent for credit information including separate consent + purpose limitation.

Artefacts an auditor will ask for
  • KR Credit Info evidence for KRCRED-2
Where this commonly fails
  • FSC + PIPC cooperation partial

Credit Information Act: Data Subject Rights and MyData

CIA-ACC-06
Data subject access, correction, and deletion rights

Data subjects have the right to access their credit information held by providers, request correction of inaccuracies, request deletion where retention is unlawful, and lodge disputes with credit inquiry companies and the FSC.

Artefacts an auditor will ask for
  • Access request handling procedure with SLA
  • Correction and deletion workflow
  • Dispute log with resolution outcomes
  • Communication templates in Korean
  • Quarterly metrics on rights request volume and timeliness
Where this commonly fails
  • Identity verification overly burdensome
  • Correction propagation to downstream users incomplete
  • Dispute outcomes not communicated within deadline
CIA-AUTOM-18
Automated decision making in credit assessment

Where personal credit information is used in automated decision making producing significant effects, data subjects have rights to explanation, contestation, and human review, and processors shall assess fairness and bias of models.

Artefacts an auditor will ask for
  • Inventory of automated credit decisions
  • Model documentation including features and methodology
  • Bias and fairness assessment reports
  • Customer notice on automated decisions and rights
  • Human review process with SLA
Where this commonly fails
  • Vendor models without transparency into features
  • No mechanism for customer contestation
  • Bias assessments limited to protected attributes not proxies
CIA-MYD-05
MyData service authorisation and operation

Entities providing personal credit information transmission services (MyData) shall obtain FSC authorisation, integrate with the central API gateway, support data subject portability requests, and meet ongoing security, capital, and operational requirements.

Artefacts an auditor will ask for
  • FSC MyData authorisation certificate
  • API integration test reports with KCB or KFTC gateway
  • Capital adequacy filings
  • Customer authentication architecture using approved methods
  • Quarterly MyData operational metrics report
Where this commonly fails
  • Authentication relying on deprecated certificates
  • Withdrawal of consent not propagated to all providers
  • Data minimisation not enforced per query

Credit Information Act: Governance and Accountability

CIA-EDU-19
Training of employees and officers

Credit information processors shall provide regular training to employees and officers handling personal credit information, with content covering legal obligations, security practices, incident response, and data subject rights.

Artefacts an auditor will ask for
  • Annual training plan
  • Attendance and completion records
  • Role specific modules for handlers, IT staff, and management
  • Assessment of learning outcomes
  • Refresher triggers based on regulatory updates
Where this commonly fails
  • Completion rates below 100 percent for required staff
  • Outsourcees not in training scope
  • Content not updated after FSC guidance changes
CIA-INSP-20
FSC and FSS inspection cooperation

Credit information processors shall cooperate with FSC and Financial Supervisory Service inspections, providing requested records and explanations within prescribed timeframes, and shall implement corrective measures resulting from supervisory actions.

Artefacts an auditor will ask for
  • Inspection response procedure
  • Records of past inspections and findings
  • Corrective action plans with status
  • Communication log with FSC and FSS
  • Internal audit linkage to supervisory findings
Where this commonly fails
  • Inspection response coordination ad hoc
  • Corrective actions closed without independent verification
  • Recurring findings indicate systemic gap
CIA-OFF-03
Credit information management and protection officer

Each credit information company and major user shall designate a Credit Information Management and Protection Officer with authority and resources to oversee compliance, report to senior management, and serve as point of contact with the FSC.

Artefacts an auditor will ask for
  • Officer appointment letter with delegated authority
  • Annual compliance plan
  • Quarterly report to board or senior management
  • Officer training certificates
  • FSC notification of designation
Where this commonly fails
  • Officer role combined with operational duties creating conflicts
  • No direct reporting line to board
  • FSC notification not updated after replacement
CIA-PRV-POL-15
Public disclosure of credit information processing policy

Credit information processors shall publicly disclose a credit information processing policy in Korean covering categories of information, purposes, retention periods, third party provision, outsourcing, data subject rights, and contact for inquiries.

Artefacts an auditor will ask for
  • Published policy on website
  • Version history with change logs
  • Notification mechanism for material changes
  • Accessibility check for Korean speakers and persons with disabilities
  • Cross reference to broader privacy policy where applicable
Where this commonly fails
  • Policy buried behind login walls
  • Updates not actively notified
  • Outsourcees listed at aggregate level only
CIA-RISK-16
Risk assessment for personal credit information

Major credit information processors shall conduct annual risk assessments specific to personal credit information, evaluating likelihood and impact of breach scenarios, and report results to senior management with risk treatment plans.

Artefacts an auditor will ask for
  • Annual risk assessment report
  • Threat scenarios specific to credit information
  • Treatment plans with owners and deadlines
  • Management acceptance of residual risk
  • Linkage to enterprise risk framework
Where this commonly fails
  • Generic information security risk substituted for credit specific assessment
  • Treatments lack milestones
  • Senior management acknowledgement missing

Credit Information Act: Lawful Basis and Consent

CIA-CHILD-17
Protection of minors credit information

Processing of personal credit information of persons under 14 years of age requires consent of a legal representative, with verification of the relationship, and additional safeguards on retention and marketing use.

Artefacts an auditor will ask for
  • Age verification mechanism
  • Legal representative verification flow
  • Records of parental consent capture
  • Marketing prohibitions enforced for minor accounts
  • Transition workflow at age 14
Where this commonly fails
  • Verification reliant on self declared age
  • Marketing exclusions not technically enforced
  • Retention beyond minor status not separately reviewed
CIA-CONS-02
Consent for provision and use of credit information

Provision or use of personal credit information for purposes beyond the original collection requires explicit informed consent from the data subject, with disclosure of recipient, purpose, items, and retention period, and consent retained for evidentiary purposes.

Artefacts an auditor will ask for
  • Consent screens with all four disclosure elements
  • Consent storage with proof of capture
  • Notification records for material changes to processing
  • Consent expiry and renewal workflow
  • Audit trail linking consent to each use event
Where this commonly fails
  • Recipient names abbreviated or grouped
  • Retention periods generic such as until purpose achieved
  • Renewal not triggered before expiry
CIA-LAW-01
Lawful basis for processing credit information

Credit information providers, users, and credit inquiry companies shall process personal credit information only on a lawful basis including data subject consent, statutory authorisation, contract necessity, or vital interests, with consent collected separately for each purpose.

Artefacts an auditor will ask for
  • Lawful basis register per processing activity
  • Consent forms with separated purpose tick boxes
  • Consent withdrawal handling procedure
  • Records of consent with timestamp
  • Annual lawfulness review minutes
Where this commonly fails
  • Bundled consent across marketing and operations
  • Withdrawal mechanism harder than collection
  • Statutory basis not documented per article
CIA-MKT-12
Use of credit information for marketing

Use of personal credit information for marketing purposes requires separate prior consent distinct from service consent, must offer opt-out at no cost, and direct marketing calls and messages must comply with electronic communications rules.

Artefacts an auditor will ask for
  • Separate marketing consent capture
  • Opt-out mechanism testing
  • Marketing suppression list integration
  • Channel specific consent (call, SMS, email)
  • Audit log of marketing communications and basis
Where this commonly fails
  • Single consent covers all channels
  • Opt-out propagation delayed across campaigns
  • Marketing through outsourcees without confirming consent
CIA-PSEUDO-04
Pseudonymised credit information processing

Pseudonymised credit information may be processed without data subject consent for statistical, scientific research, or public interest record keeping purposes, subject to technical and organisational safeguards preventing re-identification.

Artefacts an auditor will ask for
  • Pseudonymisation methodology documentation
  • Additional information storage separation evidence
  • Re-identification risk assessment per project
  • Internal approval for pseudonymised processing projects
  • Combination ledger when combining with other pseudonymised sets
Where this commonly fails
  • Direct identifiers retained adjacent to pseudonyms
  • Re-identification risk not quantified
  • Combination conducted outside specialised agencies

Credit Information Act: Outsourcing, Transfers and Licensing

CIA-INQ-13
Credit inquiry company licensing and operation

Credit inquiry companies shall be licensed by the FSC, meet capital and personnel requirements, operate with prescribed governance including independent directors and audit committees, and submit periodic operational reports.

Artefacts an auditor will ask for
  • FSC license documentation
  • Capital adequacy filings
  • Board composition and committee charters
  • Annual operational report to FSC
  • Conflict of interest policy
Where this commonly fails
  • Capital ratios calculated on stale data
  • Independent director qualifications not documented
  • Conflict declarations not refreshed annually
CIA-OUT-10
Outsourcing of credit information processing

Outsourcing of personal credit information processing requires written contract with prescribed terms, prior data subject notification, FSC reporting where applicable, supervision of the outsourcee, and inclusion of outsourcing scope in regulatory filings.

Artefacts an auditor will ask for
  • Outsourcing register
  • Contracts with FSC required clauses
  • Data subject notifications on outsourcing
  • Audit and inspection records of outsourcees
  • FSC outsourcing reports where applicable
Where this commonly fails
  • Sub-outsourcing not registered
  • Inspection frequency below requirement
  • Notification combined with privacy policy update rather than active notice
CIA-TRANS-11
Cross border transfer of credit information

Transfer of personal credit information outside Korea requires data subject consent or alternative lawful basis, disclosure of recipient country and protection level, and contractual or organisational measures ensuring equivalent protection.

Artefacts an auditor will ask for
  • Transfer impact assessment per destination
  • Standard contractual clauses or binding intra group arrangements
  • Consent capture for transfers requiring it
  • Transfer register with countries and recipients
  • Annual review of destination country protection levels
Where this commonly fails
  • Cloud provider sub-processors not in transfer register
  • Transfer assessments lack legal opinion on destination law
  • Withdrawal of consent does not stop ongoing transfers

Credit Information Act: Security, Retention and Logging

CIA-BRC-09
Breach notification to data subjects and FSC

Where personal credit information is leaked, lost, falsified, altered, or destroyed, the credit information company shall notify affected data subjects without delay and report the incident to the FSC and the Financial Supervisory Service within prescribed timeframes.

Artefacts an auditor will ask for
  • Incident response plan with credit information specific procedures
  • Notification templates for individuals, FSC, FSS
  • Breach register with timeline analysis
  • Tabletop exercise reports
  • Post incident remediation tracking
Where this commonly fails
  • Notification clock starts at confirmation rather than awareness
  • Affected individuals identified slowly delaying notification
  • FSC and FSS reports inconsistent in detail
CIA-LOG-14
Access and provision logs

Records of access to and provision of personal credit information shall be maintained for at least three years with prescribed details including identity of accessor, purpose, items accessed, and disclosure recipients, supporting investigation and audit.

Artefacts an auditor will ask for
  • Logging design covering required fields
  • Retention configuration meeting three year minimum
  • Log integrity controls
  • Periodic log review evidence
  • Anomaly detection on access patterns
Where this commonly fails
  • Bulk export logs missing item-level detail
  • Logs accessible to operators who could tamper
  • Reviews automated only without human escalation
CIA-RET-07
Retention and destruction of credit information

Personal credit information shall be retained only for the period necessary for the original purpose, with separate storage required for information retained beyond five years after termination of the commercial relationship, and destruction performed by approved methods.

Artefacts an auditor will ask for
  • Retention schedule mapping article categories
  • Separate storage architecture for legacy data
  • Destruction logs with method and date
  • Backup expiry alignment evidence
  • Annual data minimisation audit
Where this commonly fails
  • Five year separation rule applied to live datastores
  • Backups retained beyond primary destruction
  • Destruction certificates lacking method detail
CIA-SEC-08
Technical and physical safeguards

Credit information processors shall implement technical and physical safeguards including access control, encryption of personal credit information in transit and at rest, audit logging, malware protection, and intrusion detection, in accordance with FSC standards.

Artefacts an auditor will ask for
  • Information security policy aligned to FSC standard
  • Encryption inventory at rest and in transit
  • Access log retention configuration meeting minimum periods
  • Vulnerability scan reports
  • Annual penetration test report
Where this commonly fails
  • Internal application traffic not encrypted
  • Log retention shorter than required
  • Privileged access logs not separately protected

Enforcement

KRCRED-5
FSC + PIPC Cooperation, Sanctions

Per CIA: FSC + PIPC cooperation + breach notification + sanctions including criminal penalties.

Artefacts an auditor will ask for
  • KR Credit Info evidence for KRCRED-5
Where this commonly fails
  • FSC + PIPC cooperation partial

Rights

KRCRED-3
Data Subject Rights

Per CIA: data subject rights including access + correction + restriction + automated decision review.

Artefacts an auditor will ask for
  • KR Credit Info evidence for KRCRED-3
Where this commonly fails
  • FSC + PIPC cooperation partial

Scope

KRCRED-1
Scope and Purpose of Credit Information Act

Per South Korea Credit Information Use and Protection Act: scope including credit information processing + financial sector + align with FSC + PIPC.

Artefacts an auditor will ask for
  • KR Credit Info evidence for KRCRED-1
Where this commonly fails
  • FSC + PIPC cooperation partial

Security

KRCRED-4
Security, Cross-Border, Duties of Data Processors

Per CIA: security + cross-border restrictions + Duties of Data Processors + processor management.

Artefacts an auditor will ask for
  • KR Credit Info evidence for KRCRED-4
Where this commonly fails
  • FSC + PIPC cooperation partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.