Gdpr audit, sized before it starts

Updated

For the person who has to sign, a gdpr audit is a list of things to check and a number of days to check them in, and the second is decided by the first long before anyone opens the list. For a business processing personal data of people in the EU, the checks run over the record of processing, the processor agreements, the lawful bases and the requests handled; every item is a sample to take, minutes to spend and a chance of a gap that costs hours to close. The compliance officer who works those figures before the audit is scoped budgets the audit and its aftermath together; the one who does not learns the aftermath's cost from the invoice. This page walks what a gdpr audit covers, how to size its days, its expected gaps and its all-in cost, and where the free sheets on this site do that sizing from the programme's own numbers, with no account.

What a gdpr audit covers

For a business processing personal data of people in the EU: the record of processing, the processor agreements, the lawful bases and the requests handled. Each is a control with evidence behind it, and a checklist is the list of controls with a sample size and a minutes-per-sample figure attached whether or not anyone wrote them down. The audit scope sheet on this site takes systems, controls, samples and minutes and returns the samples, the hours, the days and the coverage the days available give, so the checklist has a size before it has a date.

Why the search is gdpr audit

The words in gdpr audit are the words a business processing personal data of people in the EU uses when the obligation has a name and the programme does not yet have a number. The name is the regulator's, linked below; the number is the programme's own, and it is the count of obligations, controls and evidence items behind GDPR turned into reviewer hours on the obligations register sheet and into audit days on the audit scope sheet. A programme that searches gdpr audit and comes away with those two figures has done the first day of the work, and the paid plan on this site keeps what follows: the record, with owners, dates and the attestation that closes each period.

The searches this page answers, in the words people use

Measured in the United States, the phrasings that lead here are gdpr audit (250/mo). They are one question asked 1 way: a business processing personal data of people in the EU wants to know what the record must hold and what it costs to keep, and the GDPR data-mapping sheet on this site works the figure that answers it. The wording differs; the register behind it does not, and neither does the arithmetic.

What to do with the number

Take it to the budget conversation and to the consultant's proposal. A proposal whose audit days land far from the sheet's is sampling more or less than the programme needs, and a budget that covers the assessment and not the remediation is half a budget. The guide this page supports covers scoping regulatory compliance consulting from the register. Attestvio Pro keeps every audit with its findings and their remediation against the obligations it tested; the sheets stay free.

Gaps, remediation and the all-in cost

An audit finds gaps at a rate the last audit already measured, and every gap costs remediation hours. The audit sheets on this site for HIPAA, GDPR and PCI, and the IT control-testing sheet for a framework, take the item count, the gap rate, the hours per gap and the hourly cost and return the gaps expected, the remediation hours and the cost with the aftermath in it. For GDPR the sheet to start with is the GDPR data-mapping sheet. None of them publishes a benchmark rate; each works the programme's own.

Questions people ask about gdpr audit

How long does a gdpr audit take?

Items times minutes over 60 for the hours, over the hours in an audit day for the days: the audit scope sheet on this site works it from your own systems, controls, samples and minutes with no account, and publishes no benchmark.

What does a gdpr audit cost all in?

Assessment hours plus the expected gaps times the remediation hours per gap, times the hourly cost. The audit sheets on this site work it from your own gap rate; the worked examples run from $8,800 to $19,720 for the sizes entered.

Does Attestvio run the gdpr audit?

No. Attestvio sizes it and keeps the findings and their remediation against the obligations; the audit itself is your assessor's or your own team's. The sheets are free either way.

Sources

Related answers

Start Attestvio ProGet Attestvio Pro, $29 a month