Module 9 of 9 · 6 min read
Auditor's checklist — what evidence to keep
A control-by-control checklist you can hand to internal audit or an ISO auditor.
How to use this
Each line is a control an auditor (internal, ISO 27001/27701, or an SDF independent data auditor) will test. Keep the evidence artefact named beside it. Tick the box only when the artefact exists and is current.
A. Governance
- Accountable executive and (if SDF) India-based DPO appointed — board minutes, appointment letter
- Privacy policy and internal data-protection policy approved — versioned documents
- Training delivered to staff handling personal data — attendance + assessment scores
B. Inventory & purpose
- Record of processing keyed by purpose, incl. retention and sharing — data inventory
- Children's data and employee data identified — inventory tags
- Legal-hold / statutory retention register — register
C. Notice & consent
- Notice per purpose, standalone, in required languages, with withdrawal and Board-complaint instructions — notice templates + screenshots
- Consent captured by affirmative action, unbundled — UI evidence
- Consent ledger records notice version, purpose, timestamp, channel — ledger extract
- Withdrawal as easy as giving; propagates to Processors — withdrawal test record
- Legacy data served notice — campaign report
D. Rights
- Intake channel published; identity verification defined — policy + form
- Access report can list downstream sharing — sample report
- Correction/erasure propagates to Processors with confirmation — ticket samples
- Nomination captured — UI evidence
- Grievance SLA met — ticket metrics
E. Security safeguards (Rules minimum)
- Encryption/masking/tokenisation applied — control mapping + config evidence
- Access control — IAM reviews
- Logging & monitoring, logs retained ≥ 1 year — SIEM retention config
- Backups & restore tested — restore test report
- Processor contracts carry safeguards + breach clauses — signed addenda
F. Breach management
- Runbook contains DPDPA (72 h) and CERT-In (6 h) clocks — runbook
- Templates for Principal and Board notifications — templates
- Annual table-top exercise — exercise report
- Breach register (including "no notification needed" decisions with reasons) — register
G. SDF-only
- Annual DPIA — DPIA report
- Annual independent data audit filed with the Board — audit report
- Algorithmic risk verification — assessment
- Localisation conditions honoured — data-flow evidence
H. Cross-border
- Transfers checked against Government-restricted list — review record
- Sectoral localisation (RBI etc.) still met — sector compliance evidence