Practical guides

Answer enterprise privacy and security questions honestly

Build an evidence pack that distinguishes current practice, limited coverage and planned work.

Reviewed 18 September 2026 · Prahari DPO

Create an answer record

For each customer question, identify the scope and locate the person able to approve an accurate response.

  • Question and the service or entity it concerns.
  • Proposed answer and the actual evidence supporting it.
  • Evidence owner, version, date and coverage limitations.
  • Approval, permitted sharing and unresolved follow-up.

Use precise status language

A policy drafted for approval is not an operating control. A scheduled review is not completed evidence. A supplier assertion is not an independently checked finding. Describe the current state and planned action separately.

Example: access reviews

If one team has completed a review but other systems are pending, say which systems and period are covered. Record the remaining owners and actions instead of answering an unqualified “yes”.

Share a proportionate pack

Use approved summaries or suitably redacted records. Avoid attaching employee data, secrets, unnecessary system detail or another customer’s information. Confirm who can receive any restricted assurance report.

Common questions

Can a proposed future control answer a current “yes/no” question?

Describe it as planned, with its scope and status. Do not represent a commitment as already implemented.

Should every customer get the same evidence?

Start with a maintained core pack, then check relevance, confidentiality and sharing restrictions for that request.

Discuss the work you need

Agree the service, deliverables, responsibilities and fees before committing to an engagement.

Related reading

This page explains topics to scope and discuss. It does not establish applicability, certify compliance or confirm a paid engagement.

← Practical guides