IT lead and auditor reviewing data access records on screen during a compliance audit at an Indian mid-size company office
|

Your auditor will ask about data protection this year. Here’s what to prepare.

TL;DR: Your auditor is not going to ask whether you have a data protection policy on file. Everyone has a policy on file. They are going to ask you to produce the evidence, who touched a specific customer record, on what date, under whose sign-off, and most Indian mid-size companies cannot answer that in under an hour. Here is the ten-point readiness check we run before an audit date lands on the calendar, and the one gap that catches nearly everyone.

By Priya Sharma, Data Protection Practice · Sirius Star · July 17, 2026

08:40 AM, and the internal auditor had asked for fifteen minutes with the IT lead before the main review began. A 140-person NBFC in Pune, mid-way through its annual technology risk assessment, had every policy document the checklist wanted. Data protection policy, signed. Access control policy, signed. Incident response plan, signed and laminated, practically. Then came the question that was not written on any checklist. Pull up the access trail for the loan applicant file that was updated last Tuesday. Show me who opened it, and who it was shared with after.

The IT lead opened the DMS. The file had a version history. It did not have a person history. Six people in the branch could open that folder. Nobody could say which one had.

That is the shape of almost every audit finding I have sat through this year. Not a breach. A filing problem with a deadline attached, and the deadline is usually a lot closer than the company thinks.

What the auditor is actually testing

Most owners prepare for an audit the way they would prepare for an exam, by making sure the right documents exist. That is necessary and it is also not the test. The auditor already assumes your policy folder is in order. What they are checking is whether the policy is true, whether what is written down matches what the systems can actually prove happened. A policy that says “access is logged and reviewed monthly” is a promise. The access log with a timestamp and a name against it is the evidence. Auditors under India’s DPDP Act, and under sector rules layered on top of it for BFSI and insurance, are trained to ask for the evidence first and read the policy second.

I want to be honest about a mistake, because the mistake is the lesson. Two years ago, running a readiness check for a broking client, I saw a shared drive rule forwarding a monthly reconciliation file to an external address and read it as a vendor integration, the kind of thing you note and move on from. It was not an integration. It was set up by someone who had left the company eighteen months earlier, and the rule had kept running the whole time, unnoticed, because nobody owned the review. I had treated an amber signal as background noise. It was the whole finding.

The ten checks we run before the auditor does

This is the list we walk through with a client two to three weeks before an audit date, not the week of. Doing it early is the only part that actually matters, because most of these gaps take days to close, not minutes.

CheckWhat the auditor asks forThe gap we find most often
Data inventoryWhere does personal data live, across servers, laptops, and cloud drivesA list exists, three years old, missing every device bought since
Access log with identityWho opened a specific file, not just which server logged a loginServer logs exist, file-level identity does not
Consent recordsProof a customer agreed to specific data use, retrievable per recordConsent exists in a form somewhere, not linked to the record
Data retention scheduleHow long each data category is kept and the deletion triggerNo written schedule; data is simply never deleted
Vendor data-sharing agreementsWhich third parties receive personal data and under what clauseVerbal understanding with a vendor, nothing signed
Exit process for leaversAccess revoked same day, device wiped and returned, both provenAccess revoked eventually; device wipe undocumented
Breach response drillA tested plan, not just a written one, with named ownersPlan written in 2023, never rehearsed since
Encryption at restProof, not a claim, that stored personal data is encryptedLaptops encrypted, the file server sitting next to them is not

None of these eight rows is expensive to fix on its own. What is expensive is discovering all eight together, three days before the auditor walks in, which is the week I get most of my calls.

The two things I hear before every audit call

“We haven’t had a breach, so why spend on this now.” Most companies haven’t had a breach they know about, which is a different sentence from not having had one. Data does not leave with an alarm. It leaves quietly, on a resignation, a personal email, a USB stick, and you find out when a customer, or a regulator, tells you first. The whole point of doing this readiness work is to see the gap while it is still just a gap, not read about it later as a finding.

“DPDP isn’t even being enforced yet, we’ll deal with it when it is.” Enforcement timing is genuinely a gamble, achha, nobody disputes that. But client RFPs are already starting to ask vendors about data handling before enforcement has fined a single company. The businesses that get caught scrambling after the first big penalty, and the ceiling on that penalty is ₹250 crore under the Act, will pay a premium to fix it under pressure. The ones who did this quietly now just tick the box when the auditor arrives. Later is the more expensive option every single time, that is the only reliable thing about later.

What I told the NBFC’s board

I did not tell them to buy a platform that afternoon. I told them the finding was fixable in three weeks if they treated it as a filing project, not a security scare. We rebuilt the file-level access trail on their existing DMS, added an owner to the vendor rule review so a departed employee’s forwarding rule could never sit unnoticed again, and wrote a retention schedule that matched what compliance had actually agreed to eighteen months earlier and nobody had typed up. The board’s real question, once the panic passed, was smaller than they expected: who owns this list every quarter. That question, not a purchase order, is what most companies are actually missing.

If you are doing this yourself

Start the inventory now, even a rough one, because a partial list beats a promise to make one. Assign a single named owner for access reviews, not a department, a person, because a shared responsibility is nobody’s responsibility on the day it matters. Rehearse the breach response once this year, even a tabletop version over one lunch hour, because a plan nobody has read since it was written is not a plan, it is a document. And read what the government’s own guidance actually says before you assume your industry is exempt, the Ministry of Electronics and IT’s DPDP framework page is a better source than most vendor decks, ours included.

If you want the fuller mechanics, our DPDP compliance checklist for the May 2027 deadline walks through the ten items in more depth, and our piece on who actually counts as a Data Fiduciary clears up a question that trips up almost every board I sit with. If your last conversation about this was still about the penalty number, what ₹250 crore really means for a mid-size company is worth five minutes.

Questions I get asked before every audit season

Do we need a DLP tool to pass a DPDP-related audit, or just better paperwork?

Paperwork gets you through the first question. A tool that can actually produce file-level access evidence on demand is what gets you through the second one, the one the auditor asks after reading your policy. Most mid-size companies need the evidence layer more urgently than they need a full platform.

How far ahead of an audit should we start this?

Two to three weeks, minimum. Anything closer than that turns every gap into a fire drill, and fire drills are where the real mistakes happen.

We’re not in BFSI. Does any of this apply to us?

DPDP does not carry a sector exemption. It covers personal data, full stop, which every company holds in its HR files and customer lists whether or not a regulator is watching that specific industry closely yet.

What is the single most common finding you see?

A shared drive or mailbox rule nobody remembers creating, still running, still moving data somewhere it was never meant to go after the person who set it up left the company.

Still working through what your company’s gap actually looks like before the next review lands on someone’s calendar? That is a fifteen-minute conversation, not a sales call, and it is the same one I ran with the NBFC in Pune before their board meeting.

P.S. The IT lead from that Pune NBFC called me back a month after the audit closed, just to say the follow-up review found nothing new. Not because the company had transformed. Because someone finally owned the list. That is usually the whole difference between a finding and a formality.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *