BigID Assessments
Know Your Data.
Privacy ● Protection ● Perspective
– 1 –
Privacy Impact Assessment
– 2 –
PIA Overview
Private data
attributes
Data
A Privacy Impact Assessment (PIA) is Sharing
a formal analysis and document that Information
Type of data
evaluates how personally identifiable Information
and for what
information (PII) is collected, used,
purpose that PIAs
shared, and protected
within an organization. Collect
Records of
user’s
Access consent
information
© 2025 BigID. All rights reserved. – 3 –
Assessments App Overview
– 4 –
Assessments
The BigID Assessments App helps organizations to identify, document, and mitigate risk
using industry-standard templates that comply with privacy regulations.
Within BigID, you can:
Automate Data Inventory / Discovery
Map Data to Risk
Streamline Risk Assessment Workflows
Customize PIA and Other Standard Templates
Remediate and Report on Risk
© 2025 BigID. All rights reserved. – 5 –
Assessment Steps
Remediation and
Revalidation
Select a Template Create and Use of Appropriate
Import, Clone/Copy or Edit Step Step Safeguards, assignment of
from existing template or 1 Validate 6 new assessments, internal
create new assessment attestation, or third party/
Assessments
template vendor validation, security
assessments and updating
business processes
Assign Collaborators Step Step
2 5 Risk Summary and
Assign the right individuals
for the assessment roles. Reporting
Owner, Reviewer, Responder Evaluate Risk Control Measures
Step Step
and further tasks for mitigating risk
3 4
levels
Answer or Collect Responses
Review the Responses
from Data Owners Flag Specific responses with preconfigured
Predefined or Pre Configured responses or Risks with their Probability and Impact Levels
open field answers for the assessment
© 2025 BigID. All rights reserved. – 6 –
Workflow
BigID's Assessments app walks you through the process of gathering
information from the relevant data owners, responsible parties and provides a
management interface for keeping track of these assessments.
Review
Create Assessment Collaborate Completed
Assessment Info
Create record Gather information Information in Finalize record
from respondents review by reviewers View any existing
assessments whether
completed or in progress
© 2025 BigID. All rights reserved. – 7 –
Lifecycle of a Record
Stage 1
Draft
Stage 4 Stage 2
Completed Under
Review
Stage 3
Approval
© 2025 BigID. All rights reserved. – 8 –
Stage 1: Draft
■ A newly created record automatically considered the “Draft stage.
■ Procedure:
○ Create new assessment
○ Manage collaborators
■ Select respondents, reviewers, and approvers
■ Group or Sequential approval mode can be activated here
■ Respondent Actions
○ Fill in answers
○ Mark as done
○ Add comment
© 2025 BigID. All rights reserved. – 9 –
Stage 2: Under Review
Reviewers look over each supplied answer from respondents:
■ Mark the answer as reviewed
■ Send answer back to respondent for revision (EA only)
■ Flag risks
○ Each flag risks displays-
■ Severity bar
■ Risk Name
■ Risk Case ID (from Risk Register)
■ Initials of user who flagged the risk
■ Note (if necessary)
○ The Risk Summary tab shows the list of flagged risks during the record’s review
process
© 2025 BigID. All rights reserved. – 10 –
Stage 3: Approval (optional)
Approvers look over the answers reviewed by reviewers
■ Mark answer as approved
■ Send answer to respondents for revision (EA only)
■ Flag risks
If you have defined Group approval in Settings- all your approvers will be notified and can
review the record simultaneously.
If you have defined Sequential approval- your second approver will be notified and
permitted access only after the first approver approves the record, and so on for the third,
fourth, and fifth approvers if you have configured them.
© 2025 BigID. All rights reserved. – 11 –
Stage 4: Completed
A completed record has been filled, reviewed, and approved successfully.
Actions by persona:
© 2025 BigID. All rights reserved. – 12 –
Custom Assessments
– 13 –
Customize Your Assessments
AI Assessment- helps identify, analyze and address activities associated with the
development, deployments, and/or/use of artificial intelligence which may impact the privacy,
civil, or human rights of individuals.
Data Protection Threshold Assessment (DPTA)- Determines if data protection impact
assessment (under GDPR, LGPD, or other law) is needed
Privacy Threshold Assessment (PTA)- to determine if additional assessments are warranted
Data Protection Impact Assessments (DPIA)- Helps organizations assess processing
operations that pose potential high risk of harm to individuals, the firm, and the presence or
need for further remediation measures.
Vendor Assessment- Send this to vendors or other third parties who provide services to your
organizations
+ Start From Scratch- Create your own template utilizing smart components.
© 2025 BigID. All rights reserved. – 14 –
Create/Edit Template DEMO
Summary
This demo provides a brief overview of the Assessments application:
■ Features and capabilities
■ How to create and edit a template, assign collaborators, and publish
© 2025 BigID. All rights reserved. – 15 –