Test planning, control evidence and remediation tracking

TOM Effectiveness Review: Test Your Privacy Controls

We help you test whether existing technical and organisational privacy measures work in practice.

  • 01Define traceable scope and sampling
  • 02Assess technical and organisational controls together
  • 03Connect findings to accountable owners and retests
  • 04Make review status, evidence gaps and residual risks visible
11+Years of experience
120+Employees
540+Projects
ISO 27001certified

From documented measures to tested results

A policy or configuration describes what is intended. An effectiveness review tests whether the control works within an agreed scope. ADVISORI connects the control inventory, risk-based sampling, technical tests and organisational evidence in a repeatable review process. This service focuses on existing controls; initial TOM implementation and a complete data protection impact assessment are separate assignments.

Agreed deliverables include a control inventory, test plan, test records, findings and an action tracker. Each finding receives an owner, priority, target date and retest criteria. A pilot process makes the scope and acceptance criteria concrete.

6 service modules

What we take on for you

Bookable individually or as an end-to-end programme.

01

Control Inventory and Test Planning

We map existing controls to the relevant processing activities and agree a traceable basis for review.

  • Map controls, systems and protection objectives
  • Identify owners and evidence sources
  • Explain risk priorities and sample selection
  • Record test criteria and scope
02

Technical Effectiveness Testing

We test selected technical controls using approved cases and document the observed results.

  • Test permissions for selected roles
  • Verify restoration using defined sample data
  • Compare configurations with technical evidence
  • Record results and testing limitations
03

Organisational Control Review

We examine actual cases to establish whether documented privacy procedures are being followed.

  • Sample joiner, role-change and leaver processes
  • Trace approvals and responsibilities
  • Compare training evidence with practical workflows
  • Record exceptions and missing evidence
04

Test Records and Findings Assessment

We connect test cases, evidence and assessment in a traceable review record.

  • Record date, system version and sample
  • Link findings to supporting evidence
  • Describe risk and potential consequences
  • Distinguish failed tests from untested areas
05

Remediation and Retesting

We support accountable teams in prioritising and following up the findings.

  • Assign an owner and target date to each action
  • Agree acceptance criteria for remediation
  • Plan retesting after implementation
  • Escalate unresolved risks to accountable decision-makers
06

Control Monitoring and Handover

We establish a regular view of review status, missing evidence and open actions.

  • Define metrics and their data sources
  • Expose overdue tests and actions
  • Capture changes that trigger reassessment
  • Hand over procedures and reporting templates

5 phases

Our Approach

We define the assignment with privacy, information security and process owners. A pilot checks that evidence access, test methods and assessment criteria work before extending the review to more controls.

  1. Agree scope, systems and responsible contacts

  2. Inventory controls and available evidence

  3. Run a pilot using agreed test criteria

  4. Assess findings and assign remediation owners

  5. Hand over retesting and regular reporting

Sarah Richter

Your contact

Sarah Richter

Head of Information Security, Cyber Security

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Technical and organizational privacy controls are the foundation of trustworthy data processing. Our integrated privacy control frameworks enable companies not only to achieve GDPR compliance but to use data protection as a strategic competitive advantage and build sustainable trust with customers and stakeholders.

Our Expertise

  • 01Connect privacy, information security and process review
  • 02Separate evidence, assessment and unresolved questions
  • 03Use practical technical and organisational test cases
  • 04Support the process from planning through remediation tracking

Test what the evidence actually demonstrates

Define the claim that each item of evidence must support. A successful backup log, for example, does not demonstrate a successful restoration. The test objective, steps and assessment must fit together.

19 QUESTIONS, BRIEFLY ANSWERED

Frequently asked questions about Privacy Program Technical & Organizational Controls

What is a TOM effectiveness review?

A TOM effectiveness review assesses whether technical and organisational measures provide protection in the processing activity being examined. GDPR Article 32(1)(d) provides for regular effectiveness evaluation. The assignment makes the scope, evidence and assessment criteria concrete. The EDPB guide Secure personal data also describes risk-based security and follow-up of audit actions. An inventory of measures does not by itself demonstrate that those measures work.

How are review intervals determined?

We agree intervals for each control based on the processing activity, potential consequences, frequency of change and previous findings. Frequently changed access permissions may need a different cycle from a stable organisational procedure. Incidents, material system changes and new evidence are considered as triggers for additional review. An annual review is not prescribed as a universal minimum. The rationale and next review date are recorded in the plan.

Which methods can test control effectiveness?

The method follows the objective. Access controls may be tested by comparing approved roles with a system sample; backup controls may require a planned restoration. Organisational procedures are assessed through completed cases, records and interviews. Before technical testing, we agree authorisation, sample data, operational boundaries and stop criteria. A vulnerability scan supplies only part of the evidence and does not replace assessment of organisational controls.

What belongs in a test record?

The record identifies the control, objective, steps, date, system version and sample. It links to evidence and separates observations from conclusions. Findings receive a priority, accountable owner and follow-up action. Missing evidence and untested areas are explicit. Access and retention arrangements for the review material are agreed according to its contents. A well-organised record does not guarantee legal acceptance.

How does effectiveness testing differ from implementation?

Implementation introduces a measure such as an access-management process or a restoration procedure. Effectiveness testing then examines concrete cases to determine whether the intended result is achieved. This service concentrates on test planning, evidence, findings and retests. Full technical implementation or a complete data protection impact assessment is scoped separately when needed, so the deliverables of the review remain clear.

Which metrics support control monitoring?

Useful measures include on-time reviews, overdue remediation, missing evidence and retest results. Each metric needs a clear definition, data source, accountable owner and refresh interval. A pass rate is reported alongside the scope and sample. A high score from a small set of simple checks must not conceal significant untested risks. Targets are agreed with the responsible teams rather than promised universally.

How does an ADVISORI engagement start?

We start with the processing and system inventory, existing TOM documentation, relevant evidence and responsible contacts. Together we choose a pilot and define its objectives, access, test boundaries and acceptance criteria. The pilot produces test records, assessed findings and an action list. Further scope depends on those results and available resources. The assignment does not promise certification or approval by a supervisory authority.

How is a representative sample selected?

We document the population, risk factors and selection method before testing. The sample can include different business units, privileged roles, recent changes and known exceptions. Results are interpreted within that sample rather than extrapolated automatically to every system. If a finding suggests a broader issue, the review owner decides whether to extend the sample and records the rationale.

How can access controls be tested?

An agreed test can compare approved role assignments with actual permissions and examine a small set of joiner, role-change and leaver cases. We record what access was expected, what was observed and the relevant system state. Privileged access and exceptions receive explicit attention. Tests use authorised accounts and agreed boundaries; they do not assume that a policy document proves permissions are correct.

How do you check evidence quality?

Evidence should identify the system, relevant period, source and responsible owner. We check whether it supports the specific control assertion and whether important context is missing. A screenshot without a date or configuration context may need additional support. Contradictory records remain an open issue until resolved, and missing evidence is not silently treated as a passed test.

Can controls in AI-enabled workflows be included?

Yes, when the workflow and its processing boundaries are part of the agreed scope. Example checks include access to inputs, retention settings, data export paths and the handling of test data. The review records its sample and limitations. It does not infer the legality, fairness or safety of an entire AI system from a few technical control tests.

How are training and awareness controls reviewed?

Completion records show participation but do not by themselves show that an operational procedure is followed. A review can combine those records with role-specific interviews and samples of actual work. Questions focus on the agreed process, such as recognising and escalating a suspected data incident. Findings identify practical gaps and corrective actions without assigning unsupported behavioural scores to individuals.

Can supplier evidence replace internal tests?

Supplier reports can support an assessment when their scope, period and control coverage match the service being used. We record exclusions and distinguish provider-operated controls from customer responsibilities. A certificate alone does not answer every test objective. Gaps may require additional evidence or an agreed follow-up; this review does not replace a separate assessment of contractual or international-transfer requirements.

How are cloud controls included?

We map each control to the party operating it, then identify the evidence available from the provider and customer configuration. Review cases can cover selected permissions, logging settings and restoration arrangements. A provider assurance report and a customer configuration test support different claims. The report makes those boundaries visible instead of presenting the cloud environment as universally compliant.

How do you avoid collecting excessive personal data during testing?

We agree what evidence is necessary for each objective and use suitable sample or masked data where possible. Access to working papers is limited to the review team and authorised owners. Sensitive material can be referenced at its controlled source rather than copied broadly. Retention and disposal arrangements are agreed before collection and recorded with the engagement.

What happens when a test fails?

We record the observed failure, supporting evidence and potential consequences, then agree priority and ownership with the responsible team. Immediate containment and incident handling follow the organisation’s relevant procedures where necessary. A corrective action is not closed solely because it was reported complete: the agreed evidence or retest must demonstrate that the acceptance criteria have been met.

Can testing be automated?

Automation can collect evidence or run repeatable checks when the criteria are explicit and reliable data is available. We first validate the check against a known case, define exception handling and assign an owner. Automated success does not establish every legal or organisational requirement. Manual assessment remains necessary where the result depends on context, judgement or evidence outside the system.

How are system changes reflected in the review plan?

Changes to processing, permissions, configurations or providers can make previous evidence less representative. We agree a route for notifying the control owner and deciding whether reassessment is needed. The decision records the changed scope and affected test cases. This connects change management to control review without assuming that every small change requires a complete audit.

How is the review handed over to internal teams?

The handover includes the control inventory, test instructions, evidence references, findings, action owners and reporting definitions. We walk through a sample repeat test with the operational team and record unresolved dependencies. The team should be able to explain the result and reproduce the agreed procedure. Ongoing support is scoped separately from the initial review.

Certificates, partners and more

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance