DGPSI-SOP600 an essential thought for Data Audits

The Digital Personal Data Protection Act, 2023 (DPDPA) recognizes a legal entity as a single Data Fiduciary or Significant Data Fiduciary. But in practice,  a large organization may have hundreds or even thousands of branches, subsidiaries, regional offices, functional divisions and operational units. Each of these units may independently collect, use, store, disclose and otherwise process personal data.

In such contexts, the legal entity may be one. The data-processing reality may be many.

This creates a fundamental question for the DPDPA audit:

How does an auditor audit one enterprise when the enterprise itself operates as a collection of autonomous data-processing units?

This is the question that has led to the development of DGPSI-SOP600, a proposed Standard Operating Procedure for conducting enterprise-level data audits where a Significant Data Fiduciary has multiple sub-units.

The concept of an Independent Data Auditor is going to become an important professional function in India’s emerging data protection ecosystem.

The Association of Independent Data Auditors (AIDAI), a division of the Foundation of Data Protection Professionals in India (FDPPI), has been created with the objective of developing this professional ecosystem.

AIDAI is working towards establishing professional standards under which individuals can be trained and certified as Certified Independent Data Auditors, capable of undertaking DPDPA compliance audits and related assignments such as Data Protection Impact Assessments and Algorithmic Audits.

The objective is not merely to create another certification. The larger objective is to create confidence in the audit process itself.

One enterprise does not necessarily mean one data environment

Consider a large bank. Legally, the bank may be one entity. Operationally, however, it could have thousands of branches. Each branch may interact with customers, employees, vendors and other individuals. Each branch may generate and process personal data through its own operational processes.

The same situation can arise in:

  • hospitals and healthcare networks;
  • universities and educational institutions;
  • insurance companies;
  • large retail chains;
  • manufacturing enterprises;
  • government and public-sector organizations;
  • technology companies with multiple business divisions; and
  • multinational organizations operating through regional entities.

Some of these units may perform relatively routine processing.

Others may undertake extensive or high-risk processing.

Some may themselves have characteristics that could potentially make their operations relevant to the determination of Significant Data Fiduciary obligations.

Yet the DPDPA compliance obligation ultimately has to be viewed at the level of the legal entity to which the law applies. This creates a practical audit problem. The Central Auditor cannot simply look at the corporate headquarters and conclude that the enterprise is compliant.

The auditor needs reasonable assurance that the data-processing activities occurring across the organization have also been appropriately examined.

The “Central Auditor – Sub Unit Auditor” model

This is where the concept underlying DGPSI-SOP600 becomes important.

The proposed model distinguishes between:

1. Central or Enterprise Auditor

The Central Auditor is responsible for the overall enterprise-level audit.

The Central Auditor has to understand:

  • the organization’s governance framework;
  • enterprise-wide policies;
  • common technology platforms;
  • central data-processing activities;
  • common vendors and processors;
  • enterprise-wide security controls;
  • HR and employee-data practices;
  • privacy notices and consent mechanisms;
  • data retention and deletion practices;
  • data principal rights management;
  • incident and breach management;
  • DPIA and risk-management mechanisms; and
  • the manner in which individual business units implement these requirements.

But the Central Auditor may not be able to personally audit every operational location.

A bank with 5,000 branches cannot reasonably expect one audit team to physically conduct a complete independent audit of every branch within the annual audit cycle.

2. Sub-Unit Auditor

The Sub-Unit Auditor undertakes the audit of an identified branch, subsidiary, regional office, functional division or other autonomous data-processing unit. The Sub-Unit Auditor works against a common audit standard. The findings are then communicated to the Central Auditor in a prescribed format.

The Central Auditor can therefore use the work of appropriately qualified and independent Sub-Unit Auditors as an input into the enterprise-level audit.

This is a mechanism for creating audit scalability without sacrificing standardization.

The importance of a common audit standard

There is, however, an obvious problem to be resolved. If 1,000 branches are audited by 100 different auditors using 100 different methodologies, the Central Auditor will receive 100 different interpretations of “compliance.”

The answer lies in standardization.

FDPPI has already been developing the DGPSI – Data Governance and Protection Standard of India framework, including sector-specific and functional standards such as DGPSI-Banks, DGPSI-Hospital, DGPSI-Education, DGPSI-HR and DGPSI-AI.

These standards provide a common vocabulary and a common framework for evaluating data governance and protection practices.

AIDAI proposes to build upon this foundation by establishing a common methodology for coordination between the Central Auditor and Sub-Unit Auditors.

Thus, the objective is:

Different auditors. Different locations. One audit language. One audit methodology. One consolidated assurance framework.

Why SOP600?

DGPSI-SOP600 is being conceived as the procedural layer that sits above the individual audit standards. The DGPSI framework can tell the auditor what should be examined.

SOP600 seeks to establish how multiple auditors should work together when the organization has multiple autonomous data-processing units.

Among other things, the SOP addresses the expected procedures for:

  • identifying the units that require separate audit attention;
  • determining the scope of sub-unit audits;
  • allocation of responsibilities between Central and Sub-Unit Auditors;
  • adoption of common audit standards;
  • communication between auditors;
  • reporting of audit findings;
  • treatment of deficiencies identified at sub-unit level;
  • escalation of significant findings;
  • reliance by the Central Auditor on Sub-Unit Auditor reports;
  • consolidation of findings;
  • documentation of the basis of reliance; and
  • preparation of the final enterprise-level audit report.

The detailed standard is currently under development and will be subjected to review by the Governance Body and Advisory Group of AIDAI/FDPPI.

Independence is not enough

There is another important principle behind this initiative.

The word “independent” in the context of an auditor cannot be reduced merely to the question:

“Is the auditor an employee of the organization?”

Professional independence has a much wider dimension.

The Central Auditor must have confidence that the Sub-Unit Auditor has conducted the assignment objectively. The Sub-Unit Auditor must have confidence that the methodology being followed is consistent with the enterprise audit methodology. The organization must have confidence that different auditors are not applying different standards merely because they have different professional backgrounds.

And ultimately, the Data Protection Board and other stakeholders must be able to place reasonable reliance on the integrity of the audit process.

Therefore, AIDAI’s role as a professional self-regulatory body becomes significant.

Self-regulation as a professional responsibility

AIDAI is not presently a statutory regulator. Nevertheless, a professional body can contribute significantly to the development of professional discipline.

Through:

  • common standards;
  • auditor training;
  • certification;
  • empanelment;
  • ethical requirements;
  • quality expectations;
  • peer review;
  • professional guidance; and
  • appropriate disciplinary measures,

a professional ecosystem can be created in which an auditor’s professional reputation becomes an important component of independence and accountability.

Empanelment can also provide an institutional mechanism for dealing with serious deviations from professional standards, including suspension or dis-empanelment where appropriate.

This is similar in principle to how other professional audit ecosystems have evolved around common professional standards. The objective is not to create bureaucratic control over auditors. The objective is to create trust in the audit profession.

Can the Central Auditor “rely” on another auditor?

If a Central Auditor relies upon the audit conducted by a Sub-Unit Auditor, the Central Auditor cannot simply say:

“The branch has been audited by another auditor, so I have no responsibility.”

At the same time, it would be impractical to expect the Central Auditor to repeat the entire audit conducted by every Sub-Unit Auditor. There must therefore be a structured basis for reliance.

The Central Auditor needs to know:

  • Who conducted the sub-unit audit?
  • Was the auditor appropriately qualified and independent?
  • What standard was followed?
  • What was the scope?
  • What evidence was examined?
  • What exceptions were identified?
  • Were significant deficiencies escalated?
  • Was the audit completed according to the prescribed methodology?
  • Were there unresolved disagreements?
  • Can the Central Auditor place reliance on the conclusions?

SOP600 seeks to provide the procedural architecture for answering these questions.

The financial audit analogy

The financial audit profession has already faced a similar scalability challenge. Large organizations cannot always be audited by one team examining every transaction and every location personally.

Professional standards and structured audit methodologies allow auditors to work with component auditors and rely, subject to appropriate procedures, on work performed at different components of an organization.

The data protection audit profession can learn from this experience. But there is an important difference namely that  a data audit involves governance, technology, people, contracts, processes, algorithms, security controls and the rights of individuals. T

herefore, the audit methodology has to evolve specifically for the data environment. SOP600 is an attempt to address precisely this emerging requirement.

From “audit of the organization” to “audit of the data ecosystem”

Perhaps the biggest conceptual change is this is that the DPDPA audit cannot remain a headquarters exercise”

The real data governance of an enterprise exists wherever personal data is processed.

The branch employee who collects KYC information.

The hospital employee who accesses patient records.

The HR department processing employee information.

The AI system making decisions based on personal data.

The outsourced processor handling customer information.

The regional office maintaining local records.

All of these are components of the organization’s data ecosystem.

Therefore, enterprise-level assurance must ultimately connect the governance at the centre with the processing at the edges.

DGPSI-SOP600: Building the bridge

DGPSI-SOP600 is being developed as a bridge between these two realities. Enterprise-level legal responsibility and distributed operational data processing.

The principle is simple “Central accountability does not mean centralized processing”.

And therefore, “Enterprise-level audit must be capable of absorbing distributed audit evidence.”

AIDAI’s objective is to create a system in which a Central Auditor can coordinate with qualified Sub-Unit Auditors, use a common methodology, evaluate their work, and consolidate the results into a credible enterprise-level DPDPA compliance assessment.

The challenge is substantial.  India is creating a new data protection regime. Along with it, India also needs to create the professional infrastructure that can make compliance assurance credible, scalable and trustworthy.

DGPSI-SOP600 is one step in that direction.

The detailed standard is presently under development and will be reviewed by the Governance Body and Advisory Group of AIDAI/FDPPI before its finalization.

The objective is not merely to produce another SOP. The objective is to build an audit system that can match the scale and complexity of India’s data-driven enterprises.

Naavi

(Comments are welcome)

About Vijayashankar Na

Naavi is a veteran Cyber Law specialist in India and is presently working from Bangalore as an Information Assurance Consultant. Pioneered concepts such as ITA 2008 compliance, Naavi is also the founder of Cyber Law College, a virtual Cyber Law Education institution. He now has been focusing on the projects such as Secure Digital India and Cyber Insurance
This entry was posted in Privacy. Bookmark the permalink.