The new CCPA regulations raise hard scoping questions: Are we in scope for the cybersecurity audit? Can our SOC 2 or ISO 27001 count toward it? Can our internal team run it? Is our vendor's scoring tool ADMT, and does human review change the answer? How many risk assessments do we actually owe, and who signs the attestation?
These questions are more urgent than the filing dates suggest. April 1, 2028 is when the certification gets filed. For the largest businesses, the audit period opens January 1, 2027, so the evidence has to already exist.
Join us for answers to these questions from Michael Spadea, Senior Managing Director at FTI Consulting, and a demo of how Privado's AI privacy analyst, Wren, automates audit readiness from intake to evidence.
Michael Spadea will cover scoping across all three pillars, classifying ADMT and where human review changes the answer, reusing existing security and privacy work, and why audit reports are becoming regulatory and litigation artifacts.
Ben Werner, Product Marketing Lead at Privado AI, will demo how Wren automates risk assessments end-to-end by using agents to review documentation, analyze risk, and generate reporting.