85% of AICPA Privacy Management Framework (PMF) you already have
APPI already covers about 85% of AICPA Privacy Management Framework (PMF), leaving
4 of 26 controls as genuinely new work.
Already covered 6
Likely covered 16
New work 4
What is genuinely new work
Nothing in APPI reaches these. This is the list to scope.
PMF-A.2Access Request Process
PMF-AN.3Privacy Agreements
PMF-D.1Third-Party Disclosure Controls
Show the 22 you already have
PMF-DI.2Data Quality Processes
PMF-M.3Privacy Risk Assessment
PMF-M.4Privacy Incident Management
PMF-ME.2Complaint Handling
PMF-SP.3Security Testing and Monitoring
PMF-A.1Individual Access Rights
PMF-AN.2Purpose Specification
PMF-CC.1Lawful and Fair Collection
PMF-CC.2Collection Limitation
PMF-CC.3Consent Mechanisms
PMF-D.2Third-Party Agreements
PMF-D.3Onward Transfer Accountability
PMF-M.1Privacy Program Governance
PMF-M.2Privacy Policies and Procedures
PMF-ME.1Privacy Program Monitoring
PMF-ME.3Enforcement and Remediation
PMF-SP.1Information Security Program
PMF-SP.2Security Safeguards
PMF-URD.2Retention Periods
How this is calculated
Already covered means a mapping runs from a control in APPI to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition