🔥 3-day streak
ISACA CDPSE — Certified Data Privacy Solutions Engineer57 / 147
Question 57 of 147

A privacy manager plans an audit of a critical cloud payroll processor that handles employee personal data on the organization's behalf. When defining the audit scope, the processor's contract states that on-site inspections are limited to once per year with 30 days' notice, and the processor offers an independent SOC 2 Type II report and ISO 27701 certificate as alternatives. What should the privacy manager do FIRST to ensure the audit provides adequate assurance over the processor's privacy controls?

Reviewed for accuracy · Report an issueNext question