Service offeringA practical assessment from policy intent to deletion evidence
The service can be scoped as an enterprise-wide review, a targeted assessment of priority systems or jurisdictions, or a focused examination of a known retention risk.
01Establish obligations and scope
Identify relevant business purposes, record classes, legal and regulatory drivers, contracts, internal policies, legal holds, data-residency considerations, and risk priorities.
Inputs: policies, schedules, inventories, legal summaries, audit findings, stakeholder interviews.
Outputs: scoped requirement register, assessment plan, evidence request, decision log.
02Assess controls and operating practice
Review how requirements are translated into applications, repositories, archives, backups, workflows, deletion jobs, approvals, exceptions, supplier processes, and monitoring.
Inputs: configurations, process documents, tickets, logs, samples, vendor information.
Outputs: control assessment, traceability matrix, gap findings, evidence-quality notes.
03Prioritise remediation and ownership
Rate findings using agreed criteria, define practical remediation options, clarify accountable owners, sequence dependencies, and establish measures for closure and ongoing oversight.
Inputs: risk appetite, change constraints, system roadmaps, budgets, ownership model.
Outputs: risk-ranked action plan, target controls, governance actions, KPI framework.