Organisation audit template
Organisation compliance self-assessment
Assess your own governance, policies, data protection and risk management before customers or regulators do.
4categories
16Yes/No questions
~16 minto complete
Who it's for: Founders, compliance leads and management teams.
Governance
- Are roles and responsibilities for compliance clearly assigned?
- Does management review compliance status at least quarterly?
- Is there a register of the laws and regulations that apply to you?
- Are internal audits planned and carried out?
Policies
- Are key policies (conduct, security, data protection) documented and approved?
- Have policies been reviewed in the last 12 months?
- Have employees acknowledged the policies that apply to them?
- Is there a whistleblowing channel?
Data protection
- Is there a record of the personal data you process and why?
- Are data processing agreements in place with key vendors?
- Is there a process to handle data subject requests?
- Is there a documented data breach response procedure?
Risk management
- Is there a risk register with owners and actions?
- Are third-party (vendor) risks assessed?
- Is there a business continuity plan, and has it been tested?
- Are insurance policies reviewed against current risks?
For each answer, record a short reason and attach supporting evidence (certificates, logs, photos) where available. These questions reflect general good practice; adapt them to the standards and laws that apply to you.