Simulated workplaceCAQA Meridian Business Group is a fictional business created by CAQA for training and assessment. It is not a real company and no person, client or record here is real.About this simulation
BSBCAQA MeridianSimulated workplace
Simulated workplace
Scenario · Quality, Risk and Compliance

Plan, conduct and report an internal audit of privacy and records controls

You are an Internal Auditor in the quality, risk and compliance team.

Advanced4 to 5 hours8 tasks
Home/Scenarios/Plan, conduct and report an internal audit of privacy and records controls
The situation

What has happened

The first audit in Meridian's annual program is privacy and records management, scheduled for the week of 12 October. In August a client personnel file was emailed to the wrong client contact, and an earlier audit found that closed client folders older than seven years had not been destroyed under the retention schedule. Both are open in the risk and compliance register. The Quality, Risk and Compliance Manager wants the audit planned and conducted under the Internal Audit Procedure with criteria drawn from the Privacy and Information Security Policy, the Australian Privacy Principles and the retention schedule, findings classified and recorded, and a report issued within ten business days. The auditee is the finance and administration team with people services in scope for the email incident.

Your brief. Plan the audit with a clear scope, criteria, checklist and sampling plan, conduct it from the evidence supplied, classify and record the findings with objective evidence, report in the standard format and set up corrective action follow up.
Read the work request in your inbox
Tasks

Deliverables

  • Audit plan
  • Compliance requirements list and checklist with sampling plan
  • Completed checklist with evidence
  • Classified findings and register entries
  • Audit report and closing meeting minutes
For trainers and assessors

Units of competency

Current on training.gov.au for the Business Services Training Package as at 10 September 2026.

BSBAUD511Initiate quality audits
BSBAUD512Lead quality audits
BSBAUD513Report on quality audits
BSBAUD514Interpret compliance requirements
BSBOPS504Manage business risk

Qualifications

BSB50920Diploma of Quality Auditing
BSB40120Certificate IV in Business
Assessor notes

What to look for

Evidence guide

The plan must show independence and clear criteria. The requirements list must reflect the Australian Privacy Principles accurately in plain words. Findings must cite objective evidence and be classified with reasons. The evaluation of the two open items must distinguish completed actions from effective ones. The report must follow the standard format and the improvement must address a root cause.

The student's evidence summary lists every record they created or changed in the systems named above, their notes and the tasks they ticked. Verify it against the deliverables and your own assessment tool.