Ticket Discounts for Cyber Events

GET ALERTS!

Recommended Event: Gartner Security & Risk Management Summit | 22 - 24 Sep 2026

Getting Audit-Ready for CCPA: Cybersecurity Audits, Risk Assessments & ADMT

Solution Category Application Security
Type Webinar
Organization Privado
Event Format Company Webinar

Webinar Description

Key Takeaways

  • Focuses on preparing organisations for California Consumer Privacy Act cybersecurity audits and risk assessments
  • Addresses Automated Decision-Making Technology classification requirements and human review exceptions
  • Examines how existing SOC 2 and ISO 27001 certifications apply to CCPA audit obligations
  • Designed for privacy professionals, compliance officers, CISOs and data protection leaders
  • Includes demonstration of automated audit readiness workflows using Privado AI’s Wren tool
  • Eligible for IAPP Continuing Privacy Education credits

Introduction

Getting Audit-Ready for CCPA: Cybersecurity Audits, Risk Assessments & ADMT is a live webinar designed to help privacy and compliance professionals navigate the evolving requirements of California’s landmark privacy legislation. As the California Consumer Privacy Act continues to mature through regulatory rulemaking, organisations face mounting pressure to demonstrate compliance through formal cybersecurity audits and documented risk assessments. This session addresses the practical challenges of audit preparation at a time when regulatory expectations are becoming increasingly specific and enforcement activity is intensifying.

About This Event

The webinar brings together regulatory expertise and technical demonstration to address the operational realities of CCPA compliance. Michael Spadea of FTI Consulting provides expert guidance on interpreting audit requirements and structuring compliance programmes, while Privado AI demonstrates how its Wren privacy analyst tool approaches audit readiness automation. The session is structured to move from regulatory interpretation through to practical implementation, with particular attention to evidence generation and documentation workflows.

Attendees can earn IAPP Continuing Privacy Education credits, making the session relevant for professionals maintaining certifications such as CIPP, CIPM or CIPT.

Cybersecurity Audit Scoping and Certification Alignment

One of the central questions facing compliance teams is how to scope CCPA cybersecurity audits appropriately. The regulations introduce specific audit obligations, but organisations must determine which systems, processes and data flows fall within scope. This scoping exercise has significant resource implications and directly affects audit timelines and costs.

Many organisations already maintain security certifications such as SOC 2 or ISO 27001, and a key consideration is the extent to which these existing frameworks satisfy CCPA audit requirements. While there is meaningful overlap between established security standards and CCPA expectations, the regulations introduce privacy-specific elements that may not be fully addressed by general security certifications. The webinar examines where existing compliance investments can be leveraged and where additional work may be necessary.

Automated Decision-Making Technology Requirements

The CCPA’s provisions regarding Automated Decision-Making Technology represent a relatively novel compliance challenge. Organisations deploying algorithmic systems that produce legal or similarly significant effects on consumers must understand how ADMT classification works under the regulations and when human review exceptions apply. This area sits at the intersection of privacy law and artificial intelligence governance, requiring collaboration between legal, technical and product teams.

The webinar addresses how to identify which systems qualify as ADMT, what documentation is required, and how risk assessments should account for automated processing activities. As algorithmic decision-making becomes more prevalent across industries, these requirements are likely to affect an expanding range of business operations.

Risk Assessment Documentation and Evidence Generation

CCPA regulations require organisations to conduct and document risk assessments for certain processing activities. The number and nature of required assessments depends on the organisation’s data practices, but the documentation burden can be substantial. Audit reports are increasingly treated as regulatory and litigation artifacts, meaning that the quality and completeness of documentation carries consequences beyond the immediate compliance context.

The session explores how automation can support evidence collection and assessment population, reducing manual workload while maintaining documentation quality. This is particularly relevant for organisations managing large volumes of processing activities or operating under tight compliance timelines.

Who Should Attend

The webinar is designed for professionals responsible for privacy compliance, cybersecurity governance and risk management within organisations subject to CCPA. This includes privacy officers, compliance managers, CISOs, data protection officers and legal counsel. Product and engineering leaders involved in privacy and security implementation will also find the technical discussion relevant, as will consultants and advisors supporting clients with CCPA compliance programmes.

The content is most applicable to larger enterprises and organisations with complex data processing operations, though the regulatory principles discussed apply broadly to any entity within CCPA’s jurisdictional scope.