How to Prepare for an ICO Audit: A Practical Guide for UK Businesses

16th October 2025

An audit by the Information Commissioner’s Office (ICO), also referred to as an Assessment, can be a significant event for any organisation that processes personal data. Whether it is a consensual audit (voluntary) or a compulsory audit (pursuant to the ICO’s powers under the Data Protection Act 2018), proper preparation is key to success. We have put together this step-by-step guide to help UK businesses get ready for an ICO audit, minimise disruption, and demonstrate strong data protection practices.

Why the ICO Conducts Audits

The ICO conducts audits of organisations in both the public, private and third sectors that process personal data. They assess the way that an organisation processes this personal data, checking for effective data protection policies, processes and adequate training, and also offering practical advice and recommendations. The ICO can conduct a compulsory audit based on Section 146 of the Data Protection Act 2018. In this case, the ICO issues a formal assessment notice to the organisation, detailing their requirements, i.e. providing information regarding their data processing activities. The ICO also conducts consensual or voluntary audits under Section 129 of the Data Protection Act 2018, which gives the ICO power to assess an organisation’s compliance with ‘good practice’ as defined by Section 128 of the Act.

The ICO does not conduct audits as a punishment, but to help organisations improve their data protection policies. They can help raise awareness of the organisation’s legal obligations, provide practical, tailored advice, identify any gaps in their current practices and reduce the chance of regulatory actions.

An audit can be requested by a controller, or more usually triggered by a data breach, complaint, media reports or other risk indicators; organisations should maintain strong data protection practices at all times and be proactively ready for an audit.

Audit planning: risk assessment & scoping

The ICO does not conduct audits at random – they take a risk-based, proportionate approach when deciding which organisations to audit. Factors can include complaints, a history of data breaches, new systems, high-risk processing, processing of very large amounts of data, public interest, media scrutiny, sector trends and more. 

If your organisation is selected for an audit, the first thing that will happen is an introductory meeting or call with an ICO representative to discuss the audit process. During this meeting, the scope of the audit will be agreed upon based on the specific data processing activities of the organisation, any current known risks, the amount and nature of the personal data being processed, and any sector-specific concerns relevant to the organisation. Suitable times and dates that will minimise disruption to the organisation will also be agreed upon at this time.  

What You Can Do To Prepare For An Audit

A central point of contact at your organisation should be assigned to maintain clarity and consistency before and during the audit. This person should coordinate internal responses and liaise with the ICO; if you have one, this will be your data protection officer.

Next, map out the systems and processes that will be most relevant to the audit scope – these should be identified during the preliminary meeting. These could include databases and CRM systems, data flows with third parties, records of all processing activities, any DPIAs you have undertaken, records of all data protection training, also logs of any past data breaches or similar incidents. At this stage, you should also identify any team members who are responsible for or experts in the above systems and processes, as the ICO may want to interview them.

You should also collect and organise all documentation relating to your data processing activities. Typical documents may include data protection policies, procedure manuals, guidance notes, staff training records, records of processing activities, results of Data Protection Impact Assessments (DPIAs), Legitimate Interest Assessments (LIAs), Transfer Risk Assessments (TRAs), data breach logs, and any other documents relevant to your data processing. If you have contracts with third parties or other data processors to which you transfer personal data, you should include these contracts or agreements too. 

One good practice is to run an internal or ‘mock’ audit to prepare for a real one from the ICO. This can help to check that your data protection policies reflect actual day-to-day working practices, whether staff are appropriately trained, and if the technical controls you have in place are adequate to reduce the risk of a data breach. An internal audit can also help ensure that risk assessments are in place where required and confirm that any data breach monitoring or reporting mechanisms actually work.

The ICO may want to interview team members, especially those who oversee data processing practices. Ensure these team members are available during the audit and that they are briefed on the audit’s purpose, scope and processes beforehand. 

Under the new Data (Use and Access) Act 2025, the ICO (soon to be the Information Commission (IC)) will be able to instruct controllers to commission external audits or reports, and these will also need to be provided to the ICO.

During The Audit – What To Expect

The ICO may visit your organisation in person or conduct the audit remotely, depending on what is most appropriate. This will be decided during the planning stage. The first stage of the audit will begin with an opening meeting between members of the operational and senior management team of your organisation and the ICO. This will help to clarify the aims of the audit, confirm the scope, timings and logistics, and address any concerns or issues either party may have. 

Next, the audit team will review the documented evidence and records of your data processing activities and observe your processes in practice. This can involve sampling live or anonymised data processing activities, inspecting technical safeguards, or carrying out tests on technical and organisational measures such as encryption, firewalls and access controls. They will also interview key staff members or subject matter experts on the agreed scope areas. The audit is a collaborative exercise between the ICO and your organisation; they are not there to catch you out! You should answer all their questions transparently and raise any issues or concerns promptly.

At the end of each day, the audit team will highlight any areas of concern they have uncovered to their contact within your organisation, giving you the chance to investigate further or provide additional evidence of compliance. If the auditors discover a data breach during their audit, they will inform your organisation as quickly as possible, explain what needs to be done, and what the next steps should be. 

The audit team will hold a closing meeting with your organisation’s key stakeholders. This meeting is to summarise their findings, concerns and positive practices, explain the next steps, and begin to arrange any follow-up work. They will follow up with a draft report within around 10 working days of completion of the audit.

Reports, Action Plan & Follow-up

The draft report from the ICO will contain an assurance rating on each scope area that was examined during the audit. These ratings go from ‘high assurance’ to ‘very limited assurance’ – see this table below from the ICO website for more information.

Source: ico.org

This draft report also contains any non-conformities and their associated risks, and includes prioritised recommendations that would mitigate said risks. This gives you a chance to either accept, partially accept or reject their recommendations, and prepare an action plan for implementation of their recommendations. Your response should include realistic timelines, resource allocations and accountability.

Once you submit responses and adjustments, a final report is issued along with an executive summary published on the ICO website. This contains the background, scope and audit approach, recommendations and assurance ratings. Detailed findings will not be published. 

The ICO may arrange a follow-up audit to check that you have implemented key recommendations – especially high or urgent ones. They’ll focus on areas of greatest risk. They will not publish the follow-up summary online, but may publish a note that follow-up work has been undertaken. 

In extreme cases where significant non-compliance remains unaddressed, the ICO retains the right to take regulatory or enforcement action. 

How the ICO Handles Rejected Recommendations

Why would an organisation reject the ICO’s draft report and their recommendations? There could be grounds to disagree, based on incomplete or inaccurate information, differing interpretations or legal requirements, disproportionate suggestions, or impracticalities due to system limitations.

Rejecting a recommendation does not automatically create conflict. The ICO expects organisations to justify their position clearly and provide supporting evidence or alternative actions. The ICO then reviews this response and decides whether to amend its report, maintain its position, or note the disagreement in the final version.

If the ICO considers the rejection unreasonable or high-risk, it may flag this in the final report, potentially triggering follow-up engagement, monitoring, or enforcement activity. However, where a rejection is well-reasoned, supported by evidence, and shows ongoing commitment to compliance, the ICO typically records it without escalation.

Preparing for an ICO audit may seem daunting, but taking a methodical approach can turn it into a valuable opportunity. Far from being merely a regulatory “test,” the audit process is designed to help you discover gaps, mature your practices, and build trust in your data protection approach.

By following the steps above – clarifying audit scope, gathering and verifying your evidence, running internal reviews, preparing staff, engaging cooperatively during the audit, and committing to post-audit improvement – you put your organisation in the strongest possible position.

If you need some help planning for your audit with the ICO, or preparing an internal audit, we can help – get in touch with Griffin House Consultancy here or call us on 01673 885533 for a chat.

 

Author: Mike Martin LLM

Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details