"The structure, the practice exams, the instructor — all top tier. Passed first try."
Course Outline
What the programme covers, module by module.
Module 1: Introduction to ISO 27701
- ISO 27701 overview
- Purpose and scope
- Privacy information management
- PIMS concepts
- Personally identifiable information
- Key terminology
Module 2: Understanding the PIMS Framework
- PIMS structure
- Privacy management principles
- Organisational context
- PIMS boundaries
- Process approach
- Privacy management lifecycle
Module 3: Privacy Roles & Responsibilities
- PII principals
- PII controllers
- PII processors
- Responsibility allocation
- Organisational accountability
- Privacy responsibilities
Module 4: Organisational Context & Governance
- Internal and external context
- Interested parties
- Privacy requirements
- Leadership responsibilities
- Privacy policies
- Governance structures
Module 5: Privacy Risk Management
- Privacy risk concepts
- Risk identification
- Privacy threats
- Impact considerations
- Risk analysis
- Risk treatment
Module 6: PII Lifecycle Management
- PII collection
- Storage
- Processing
- Sharing and transfer
- Retention
- Secure deletion
Module 7: Privacy Controls
- Access control
- Authentication
- Authorisation
- Information protection
- Data minimisation
- Privacy control implementation
Module 8: Privacy by Design & Default
- Privacy by design
- Privacy by default
- Purpose limitation
- Data minimisation
- System considerations
- Integrating privacy controls
Module 9: PII Controller Responsibilities
- Processing purposes
- Privacy information
- PII principal requests
- Consent considerations
- Processing records
- Controller accountability
Module 10: PII Processor Responsibilities
- Processing instructions
- Processor responsibilities
- Customer information
- Subprocessor considerations
- Data return
- Data deletion
Module 11: Third Parties, Transfers & Disclosure
- Third-party processing
- Supplier relationships
- PII transfers
- Data location
- Disclosure requests
- Transparency
Module 12: Privacy Incident Management
- Privacy incidents
- Incident identification
- Reporting
- Escalation
- Response activities
- Incident documentation
Module 13: Internal Audit Fundamentals
- Internal audit purpose
- Audit principles
- Independence
- Objectivity
- Professional conduct
- Evidence-based auditing
Module 14: Establishing an Internal Audit Programme
- Audit programme objectives
- Audit scope
- Audit frequency
- Audit priorities
- Resource requirements
- Auditor responsibilities
Module 15: Audit Planning & Preparation
- Defining audit objectives
- Establishing scope
- Audit criteria
- Audit schedules
- Reviewing documentation
- Preparing audit activities
Module 16: PIMS Documentation Review
- Privacy policies
- PII inventories
- Processing records
- Risk documentation
- Procedures
- Previous audit information
Module 17: Developing Audit Checklists
- Checklist objectives
- Requirement-based questions
- Controller controls
- Processor controls
- Privacy risk questions
- Audit trails
Module 18: Conducting PIMS Audit Activities
- Opening meetings
- Interviews
- Observations
- Document review
- Record review
- Following audit trails
Module 19: Gathering & Evaluating Audit Evidence
- Objective evidence
- Evidence sources
- Sampling
- Evidence sufficiency
- Evidence reliability
- Evaluating control effectiveness
Module 20: Audit Findings & Nonconformities
- Evaluating conformity
- Identifying gaps
- Classifying findings
- Supporting evidence
- Writing clear findings
- Improvement opportunities
Module 21: Audit Reporting & Closing Meeting
- Audit conclusions
- Report structure
- Findings summary
- Closing meeting
- Communicating results
- Management feedback
Module 22: Corrective Actions & Audit Follow-Up
- Corrections
- Root cause concepts
- Corrective actions
- Reviewing responses
- Effectiveness verification
- Continual improvement
Who it's for & what's included
Pick a delivery method to see exactly who it suits and everything you receive.
Classroom
Best for learners who want face-to-face tuition and to network with peers in person.
Everything you get
- ✓ Live instructor on-site
- ✓ Printed workbook & materials
- ✓ Group exercises & case studies
Online Instructor-Led
Best for learners who want a live instructor and a fixed schedule, without the travel.
Everything you get
- ✓ Live instructor via video call
- ✓ Digital workbook & resources
- ✓ Session recordings
Self-Paced
Best for self-motivated learners who need maximum flexibility around work and life.
Everything you get
- ✓ On-demand video lessons
- ✓ Interactive quizzes
- ✓ 24/7 access on any device
Course Overview
The ISO 27701 Privacy Information Management Internal Auditor course equips working professionals with practical knowledge for conducting internal PIMS audits. Learners explore ISO 27701 requirements, privacy governance, PII controller and processor responsibilities, privacy risks, information lifecycle controls, audit principles, planning, evidence collection, interviews, findings, reporting, corrective actions, and follow-up activities.