Independent Data Auditors..Should they be rotated every 2 or 3 years?

In continuation of our discussions on how to maintain independence of the “Independent  Data Auditors” in a DPDPA compliance scenario, we discussed the need for share holders to approve the appointment so that the auditor does not feel obligated to the management which makes the payments.

One other best practice criteria which Naavi would like to suggest is  that no Data Auditor should continue to audit the same company for more than  3 consecutive years. This is also consistent with the norms adopted by the statutory financial auditors.

This will be currently suggested for the empanelled auditors of AIDAI as part of the self regulation of the auditors as an ethical conduct.

FDPPI in its mechanism for regulating the Certification partners who conduct their audits would include this as a requirement so that auditors who donot adhere to this norm may lose the accreditation status.

Currently we shall try to include this in the Code of Conduct for AIDAI empanelled Auditors and try to implement it.

Naavi

 

About Vijayashankar Na

Naavi is a veteran Cyber Law specialist in India and is presently working from Bangalore as an Information Assurance Consultant. Pioneered concepts such as ITA 2008 compliance, Naavi is also the founder of Cyber Law College, a virtual Cyber Law Education institution. He now has been focusing on the projects such as Secure Digital India and Cyber Insurance
This entry was posted in Privacy. Bookmark the permalink.