Compliance Toolkit/Data Audit Checklist
KPLR/CHK/006/2026 Standalone Checklist Data Mapping & Governance
Compliance Toolkit · Standalone Checklist

Data Audit Checklist

A Practical Data Mapping & Governance Guide

Prepared by
Muchangi Patrick & Co. Advocates
Published
July 2026
Format
26 items · Fillable PDF
Version
1.0
Editorial Status
Published
Language
English
Abstract

A board-level, self-assessment instrument prepared by Muchangi Patrick & Associates Advocates — 26 scored requirements, a compliance score band, and a priority action plan.

How to Use This Checklist

For each requirement below, record one of four ratings: YES — fully compliant; PARTIAL — a defined gap remains; NO — the requirement is unmet; N/A — not applicable to the organisation's operations. Download the fillable PDF to complete and retain your assessment.

Executive Summary

Periodic data audits enable an organisation to maintain an accurate record of processing activities, identify unknown or unauthorised data flows, and demonstrate accountability in accordance with section 41 of the Data Protection Act, 2019. This checklist has been prepared by Muchangi Patrick & Associates Advocates to guide organisations through a structured data mapping and audit exercise, from data inventory and classification to reporting and remediation.

How to Use This Checklist

This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes.

Data Audit Assessment

No.RequirementYesPartialNoN/A
01All personal data holdings identified and catalogued
02Data inventory or map covering all departments completed
03Categories of data subjects identified
04Categories of personal data identified, including special categories
05Sources of personal data documented
06Purpose of collection recorded for each data category
07Lawful basis identified for each processing activity
08Data flows within the organisation mapped
09Data flows to external third parties mapped
10Cross-border data transfers identified and documented
11Data storage locations identified (on-premise, cloud or hybrid)
12Data retention periods defined for each data category
13Data disposal and secure deletion procedures verified
14Processor and sub-processor relationships identified
15Data processing agreements in place with all processors
16Access controls reviewed for each data repository
17Data quality and accuracy controls assessed
18Legacy or orphaned data systems identified
19Shadow IT and unauthorised data repositories investigated
20Records of Processing Activities (ROPA) updated
21Data protection risks identified during the audit
22Findings compared against the previous audit cycle
23Remedial actions assigned with owners and timelines
24Audit findings reported to senior management or the board
25Data audit methodology and scope documented
26Next audit cycle scheduled

Compliance Score

Aggregate the ratings above to determine the organisation's overall compliance posture:

ScoreAssessment
23 – 26Excellent
18 – 22Good
11 – 17Fair
0 – 10Immediate Remediation Required

Priority Action Plan

Corrective actions identified during the assessment should be recorded and tracked to closure, assigned by priority (High / Medium / Low) to a named responsible officer with a target date — see the fillable PDF for a ready-made tracking table.

Overall Assessment

Record an overall rating of Excellent, Good, Moderate/Fair or Poor, together with the auditor's notes, in the space provided in the fillable PDF.

Disclaimer: This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes. Reading this publication does not create an advocate-client relationship with Muchangi Patrick & Associates Advocates. For advice on a specific matter, please book a consultation.
PM

Patrick Muchangi

Advocate of the High Court of Kenya · Founder, Muchangi Patrick & Associates Advocates

Patrick Muchangi is an Advocate of the High Court of Kenya and founder of Muchangi Patrick & Associates Advocates, a Nairobi practice specialising in data protection, privacy, AI governance and technology law, and editor of the Kenya Privacy Law Review.