Plan, conduct and report an internal audit of privacy and records controls
You are an Internal Auditor in the quality, risk and compliance team.
What has happened
The first audit in Meridian's annual program is privacy and records management, scheduled for the week of 12 October. In August a client personnel file was emailed to the wrong client contact, and an earlier audit found that closed client folders older than seven years had not been destroyed under the retention schedule. Both are open in the risk and compliance register. The Quality, Risk and Compliance Manager wants the audit planned and conducted under the Internal Audit Procedure with criteria drawn from the Privacy and Information Security Policy, the Australian Privacy Principles and the retention schedule, findings classified and recorded, and a report issued within ten business days. The auditee is the finance and administration team with people services in scope for the email incident.
Deliverables
- Audit plan
- Compliance requirements list and checklist with sampling plan
- Completed checklist with evidence
- Classified findings and register entries
- Audit report and closing meeting minutes
Documents to use
Systems to use
Risk and Compliance Register
Holds Meridian's risks, incidents, audit findings and compliance obligations with ratings, owners, treatments and review dates.
Projects Register
Tracks client and internal projects with their manager, dates, budget and stage, and holds milestones and status reports.
Client Relationship Manager
Holds every client and prospect with their segment, service line, engagement value, contacts and the log of interactions and actions.
Units of competency
Current on training.gov.au for the Business Services Training Package as at 10 September 2026.
BSBAUD511Initiate quality auditsBSBAUD512Lead quality auditsBSBAUD513Report on quality auditsBSBAUD514Interpret compliance requirementsBSBOPS504Manage business riskQualifications
BSB50920Diploma of Quality AuditingBSB40120Certificate IV in BusinessWhat to look for
Evidence guide
The plan must show independence and clear criteria. The requirements list must reflect the Australian Privacy Principles accurately in plain words. Findings must cite objective evidence and be classified with reasons. The evaluation of the two open items must distinguish completed actions from effective ones. The report must follow the standard format and the improvement must address a root cause.