By assessing the adequacy of management ‘s identification of risks related to its privacy objectives and adequacy of the control established to mitigate those risk.
IA activity needs appropriate knowledge to conduct an assessment of the risk and controls of the organization’s privacy framework.
If the internal auditor assumes any responsibility for developing and implementing a privacy program. The internal auditor’s independence will be impaired.