Evidence over Aspiration: Building an Audit-Ready Privacy Practice

Why policies and commitments are not enough - and how structured PIIAs create the evidence of real accountability

Many organisations can point to privacy policies, training records and statements of commitment. These are necessary elements of a compliance programme. They are not, on their own, sufficient evidence that personal information is being processed in accordance with the Protection of Personal Information Act (POPIA).

POPIA requires responsible parties to process personal information lawfully and to take reasonable technical and organisational measures to protect it. Information Officers must ensure that a Personal Information Impact Assessment (PIIA) is conducted so that adequate measures and standards exist to comply with the conditions for lawful processing. When questions arise - from the Information Regulator, from auditors, or from the board - the organisation needs more than aspirational statements. It needs evidence of the work that has been done.

An audit-ready privacy practice is built on records that show how decisions were reached. A well-conducted PIIA contributes directly to this. It documents the nature of the processing activity, the purposes being pursued, the personal information involved, and the assessment of necessity and proportionality. It records the risks identified, the controls evaluated, and the conclusions reached about residual risk. This creates a trail that can be examined and understood by someone who was not involved in the original activity.

Without this level of documentation, organisations often rely on generalised assurances. Policies may state that data minimisation is applied, yet provide little indication of how that principle was considered in a specific system. Security measures may be described at a high level, without clear evaluation of whether they adequately address the risks associated with a particular processing activity. In an audit or regulatory engagement, these gaps become difficult to explain.

A structured assessment process reduces that difficulty. By following a consistent method - examining context, lawful processing conditions, information security risks, and formal validation - organisations produce records that are comparable, reproducible and capable of supporting scrutiny. The quality of the analysis matters. Assessments that remain superficial provide limited assurance. Assessments that engage carefully with the details of the processing provide stronger evidence of accountability.

This becomes especially relevant when organisations use artificial intelligence or other complex systems. These technologies often involve multiple data sources, automated decision-making, and outcomes that can affect individuals in material ways. Demonstrating that privacy risks were considered requires more than a policy reference. It requires documented examination of the specific activity and the controls applied to it.

King V reinforces the importance of evidence at governance level. Boards are expected to oversee data, information and technology and to maintain appropriate accountability. High-level reports that speak only of commitment leave governing bodies with limited visibility. Clear records of privacy assessments and the decisions arising from them provide a more reliable basis for oversight.

Building an audit-ready practice does not require perfection. It requires discipline. Processing activities that are likely to affect data subjects should be assessed with appropriate care. Findings should be recorded in a way that can be retrieved and understood. Assessments should be reviewed when significant changes occur. Over time, this creates a body of evidence that reflects how the organisation actually manages personal information, rather than how it aspires to do so.

POPIA is concerned with the substance of compliance. Policies set direction. Training builds awareness. Evidence shows whether the requirements are being met in practice. A structured approach to Personal Information Impact Assessment helps organisations move from aspiration to demonstrable accountability. In an environment of increasing regulatory and governance scrutiny, that distinction is becoming more important.