ON-DEMAND WEBINAR

Getting Audit-Ready for CCPA: Cybersecurity Audits, Risk Assessments & ADMT

75
minutes

The new CCPA regulations raise hard scoping questions: Are we in scope for the cybersecurity audit? Can our SOC 2 or ISO 27001 count toward it? Can our internal team run it? Is our vendor's scoring tool ADMT, and does human review change the answer? How many risk assessments do we actually owe, and who signs the attestation?

These questions are more urgent than the filing dates suggest. April 1, 2028 is when the certification gets filed. For the largest businesses, the audit period opens January 1, 2027, so the evidence has to already exist.

Join us for answers to these questions from Michael Spadea, Senior Managing Director at FTI Consulting, and a demo of how Privado's AI privacy analyst, Wren, automates audit readiness from intake to evidence.

Michael Spadea will cover scoping across all three pillars, classifying ADMT and where human review changes the answer, reusing existing security and privacy work, and why audit reports are becoming regulatory and litigation artifacts.

Ben Werner, Product Marketing Lead at Privado AI, will demo how Wren automates risk assessments end-to-end by using agents to review documentation, analyze risk, and generate reporting.

In this webinar, you'll learn

  • Article 9: When existing SOC 2 or ISO 27001 work may be relied on, and what has to be supplemented, the independence and reporting line conditions an internal audit function has to meet, and how a readiness assessment run under counsel before the audit period opens changes what the auditor finds
  • Article 10: How to scope risk assessments across all the triggering categories, consolidate comparable processing activities into a single assessment, and meet the 45-day material change window
  • Article 11: How to classify ADMT, when a human reviewer qualifies for the opt-out exception, and what pre-use notices and access responses have to include
  • Automation: How Privado AI’s Wren analyzes risk, populates assessments, and generates evidence for the CalPrivacy submission package

The IAPP (International Association of Privacy Professionals) has approved for webinar attendees to receive 1.25 CPE credit towards the following IAPP certifications: AIGP, CIPP/A, CIPP/C, CIPP/CN, CIPP/E, CIPP/US, CIPM, CIPT.

To receive CPE credits, attendees must self-report attendance by doing the following:

  • Access your IAPP account and navigate to the CPE Submission Form
  • Select “Non-IAPP Event or Online Program (web conference): Attendee” or “CPE/Other” on the Activity drop-down menu
  • Choose the applicable certification(s) you would like to submit the CPE credits for
  • Enter the date of the event and the number of CPE credits earned. In the Notes section, add the title of the event
  • Hit submit! The credits are immediately added to your account

Still have questions? Send a note to cpe@iapp.org

ON-DEMAND WEBINAR

Getting Audit-Ready for CCPA: Cybersecurity Audits, Risk Assessments & ADMT

75
minutes