Skip to main content
FaizZab

Readiness assessment

ISO 27701 Privacy Readiness Assessment

Test the strength of your privacy management system before formal conformity assessment.

The business problem

Why organizations bring this to us

Privacy programmes are unusually good at looking complete. The notice is published, the policy is approved, the register exists in a spreadsheet, and the team believes the position is sound - until someone samples ten rights requests and finds four with no record of what was actually returned.

This assessment applies evidence sampling to privacy the way an assurance provider would. It establishes whether the privacy management system produces proof, and identifies the specific places where accountability breaks down before a conformity assessment or a customer audit finds them.

Who this is for

  • Organizations with an established privacy programme preparing for conformity assessment or certification.
  • Processors facing privacy audits from controller customers.
  • Privacy leads who need an independent view of programme condition to support a budget or resourcing case.
  • Organizations that have implemented privacy controls in parts of the business but not consistently.

Service scope

Assessment areas

The review is driven by sampling. Wherever the privacy management system claims a control operates, the assessment asks for the record that proves it.

PIMS Boundary Assessment

Test whether the declared privacy management system boundary matches actual processing, including business units, jurisdictions and systems that fall outside the documented scope.

Privacy Accountability Review

Establish whether privacy accountability is genuinely exercised - decisions made, escalations raised, resource allocated - or whether it exists as a job title without authority.

Processing Transparency Evidence

Compare what the organization tells individuals about processing with what systems and contracts show it actually does, and surface the gaps between the two.

Controller / Processor Obligation Mapping

Verify role determination per processing activity and confirm that the obligations attached to each role are reflected in contracts, processes and evidence.

Privacy Notice Quality

Assess notices for completeness, accuracy, accessibility and currency, including whether they were updated when processing changed.

Rights-Handling Evidence

Sample actual rights requests end to end - receipt, identity verification, system search, response, timeline and record - and report the completion and evidence rate.

Processor Oversight

Test whether processors were subject to due diligence, carry appropriate contractual terms, disclose sub-processors, and are actually monitored after onboarding.

Privacy Risk Documentation

Review privacy risk and impact assessments for coverage, timing and quality, and confirm whether identified risks were tracked to a decision.

PIMS Assurance Heatmap

Present a single view of privacy control condition across the management system, showing where assurance is strong, partial or absent.

Priority Remediation Plan

Sequence remediation by regulatory exposure, individual impact and assessment barrier, so effort is spent on the gaps that carry consequence.

Methodology

How the assessment runs

  1. Documentation and register review

    Analyse the PIMS documentation, processing records, notices and contracts prior to fieldwork.

  2. Processing walkthroughs

    Trace selected high-volume or high-sensitivity processing activities through the systems that handle them.

  3. Rights and processor sampling

    Sample real rights requests and real processor onboarding files and test them against required practice.

  4. Gap classification

    Classify each finding by regulatory exposure, impact on individuals and barrier to conformity assessment.

  5. Heatmap and roadmap

    Deliver the assurance heatmap and a prioritized remediation plan with owners and sequencing.

What you receive

Key deliverables

  • PIMS readiness report with area-level ratings
  • Boundary and scope findings
  • Controller / processor obligation mapping results
  • Transparency comparison between notices and actual processing
  • Rights-handling sampling results with completion and evidence rates
  • Processor oversight findings including sub-processor visibility
  • PIMS assurance heatmap
  • Priority remediation plan with owners and sequencing

Outcome

See where privacy governance stands - with evidence, not assumptions.

Commercial value

Why this service matters

Proof, not posture

Conformity assessment and customer audits both test records. Knowing which records do not exist is the difference between a controlled remediation and a public finding.

Contractual exposure

Processor obligations flow through contracts. Mapping them to actual practice surfaces commitments the business has made but is not meeting.

Credible reporting

An independent heatmap gives privacy leads a defensible basis for reporting programme condition to leadership.

Questions

Common questions

Do you sample real personal data during the assessment?

No. Sampling is performed on process records and metadata - request logs, assessment outputs, contract files - and is designed to avoid unnecessary exposure of personal information.

Can this be combined with an ISO 27001 readiness assessment?

Yes. Because ISO/IEC 27701 extends the security management system, combining the two assessments avoids duplicate interviews and produces a single integrated remediation roadmap.

Does this cover India DPDP obligations?

The PIMS assessment covers privacy management system condition. Where DPDP applicability is also in question, our India DPDP readiness assessment addresses those obligations specifically.

Related

Related services

View all services
ImplementationAVAILABLE NOW

ISO 27701 Implementation

Implementation of a Privacy Information Management System aligned to ISO/IEC 27701:2025 - privacy governance and accountability, controller/processor role modelling, personal information lifecycle, processing inventory, rights handling and privacy evidence architecture.

Explore this service
Readiness assessmentAVAILABLE NOW

India DPDP Readiness Assessment

A structured assessment of DPDP preparedness - applicability profiling, obligation mapping, phased-commencement readiness, notice and consent testing, rights and grievance walkthroughs, breach preparedness and a risk-ranked remediation programme.

Explore this service
Readiness assessmentAVAILABLE NOW

ISO 27001 Readiness Assessment

An evidence-based benchmark of your existing ISMS against ISO/IEC 27001:2022 certification expectations - clause and Annex A readiness, documentation sufficiency, evidence sampling, and a prioritized 30/60/90-day remediation roadmap.

Explore this service
AdvisoryAVAILABLE NOW

Third-Party Risk

Design and operation of third-party risk management - supplier due diligence, criticality tiering, risk assessment, contractual controls, ongoing monitoring and periodic review.

Explore this service

Important

Readiness and advisory support only. This assessment is not legal advice and does not constitute a conformity assessment or certification. FaizZab does not issue ISO certification. Legal interpretation should be validated with qualified legal counsel.

Find out where you actually stand

Tell us your obligation, your timeline and where you are today. We will confirm whether this is the right engagement for you.