About this course
This course covers auditing a Privacy Information Management System against ISO 27701, extending ISO 27001, including data protection impact assessments and privacy controls.
Everything you get
✓
Live instructor-led sessions
✓
Downloadable templates and working documents
✓
Full learning management system access
✓
Realistic simulated audit case study
✓
Digital certificate on successful completion
Learning outcomes
OUTCOME 1
Explain the PIMS framework and ISO 27701 requirements
OUTCOME 2
Audit data protection impact assessments and privacy controls
OUTCOME 3
Plan, conduct, report and follow up a PIMS audit
OUTCOME 4
Evaluate privacy governance and accountability practices
Practical, job-ready skills
Where this can take you
Step 1
Internal PIMS Auditor
Audit your organization's privacy information management system.
Step 2
PIMS Lead Auditor
Lead certification audits for third-party bodies.
Step 3
Data Protection Officer
Oversee organization-wide privacy compliance.
Course modules
1
Module 1: PIMS Fundamentals & ISO 27701 Framework
2
Module 2: Audit Principles & Auditor Roles
3
Module 3: Data Protection Impact Assessment Review
4
Module 4: Conducting the Audit
5
Module 5: Auditing Privacy Controls & Governance
6
Module 6: Nonconformities & Reporting
7
Module 7: Closing Meetings & Corrective Action
Format & delivery
✓
Live virtual instructor-led sessions
✓
One continuous case study audited end-to-end
✓
Choice of intensive or part-time schedule
How you're assessed
Assessment is continuous through in-course activities, plus a final objective examination lasting approximately 1 hour 30 minutes, open book. A certificate is issued shortly after a passing result.
Who should attend
- Data protection officers and privacy managers
- Information security professionals
- Internal auditors moving to certification auditing
- Professionals pursuing PIMS lead auditor certification
Frequently asked questions
What does this course cover? +
ISO 27701 requirements, data protection impact assessments, and PIMS auditing.
Who should attend? +
Data protection officers, privacy managers, and information security professionals.
How long is the course? +
32 hours over 4 days.
Do I need ISO 27001 knowledge first? +
Helpful but not mandatory; the course covers relevant ISO 27001 concepts.
What is the exam format? +
Open book, objective questions, approximately 1 hour 30 minutes.