Description:
Organizations increasingly depend on data to support business decisions, regulatory compliance, cybersecurity, privacy, and AI initiatives. Yet data related audits remain underrepresented in audit plans until significant issues occur. This session provides auditors with a practical, risk-based approach to evaluate data governance and management practices across the data lifecycle. Participants will learn how to identify key risks, align audit efforts with leading frameworks, assess critical control domains, and understand how AI is impacting the data lifecycle. Attendees will be equipped with actionable strategies for incorporating data into your audit plan and delivering impactful assurance.
Learning Objectives:
- Differentiate data governance from data management and evaluate accountability structures that influence organizational risk and audit coverage.
- Apply a risk-based methodology to scope and plan audits across the data lifecycle, including regulatory, operational, technology, and AI-related considerations.
- Assess the effectiveness of key controls supporting data quality, classification, privacy, security, retention, and regulatory compliance.
- Identify emerging risks associated with AI and evaluate how data governance practices influence the reliability, security, and ethical use of AI technologies.
Speaker: Terry Waters, CISSP, CISA, AAIA, CDPSE, Audit Advisor, Cybersecurity and IT Risk
Access until: 12 pm CT on 14 January 2027