Free tool How audit-ready is your organisation? Get your score in 3 minutes. Take the readiness check

Organisation audit template

Organisation compliance self-assessment

Assess your own governance, policies, data protection and risk management before customers or regulators do.

Use this template in Vexsai
4categories
16Yes/No questions
~16 minto complete

Who it's for: Founders, compliance leads and management teams.

Governance

  1. Are roles and responsibilities for compliance clearly assigned?
  2. Does management review compliance status at least quarterly?
  3. Is there a register of the laws and regulations that apply to you?
  4. Are internal audits planned and carried out?

Policies

  1. Are key policies (conduct, security, data protection) documented and approved?
  2. Have policies been reviewed in the last 12 months?
  3. Have employees acknowledged the policies that apply to them?
  4. Is there a whistleblowing channel?

Data protection

  1. Is there a record of the personal data you process and why?
  2. Are data processing agreements in place with key vendors?
  3. Is there a process to handle data subject requests?
  4. Is there a documented data breach response procedure?

Risk management

  1. Is there a risk register with owners and actions?
  2. Are third-party (vendor) risks assessed?
  3. Is there a business continuity plan, and has it been tested?
  4. Are insurance policies reviewed against current risks?

For each answer, record a short reason and attach supporting evidence (certificates, logs, photos) where available. These questions reflect general good practice; adapt them to the standards and laws that apply to you.