Q: How often should we test compliance controls?
CLICBrain: There isn’t one frequency appropriate for every control. Testing frequency can depend on factors such as: the importance of the control; the risk if it fails; how frequently the process operates; whether the system or vendor has changed; previous findings; complaints or incidents; and applicable legal or contractual requirements.
A high-risk, frequently used control may deserve more frequent testing than a low-risk process that rarely changes. The important point is to avoid leaving testing entirely to chance.
For significant controls, organizations should consider establishing: what will be tested; who will test it; how often testing will occur; what evidence will be retained; and how failures will be corrected and retested.
Have another compliance question? Ask CLICBrain on CLIClaw.com.
CLICBrain Weekly Briefings provide operational compliance intelligence and commentary for internet businesses. Regulatory developments, enforcement activity, and legal requirements discussed herein should be evaluated in the context of your organization’s specific operations, systems, data practices, jurisdictions, and risk profile. This briefing is for informational and educational purposes only and does not constitute legal advice.
