Skip to main content

Record breaches and audit activity

Record breaches and audit activity

Use this when... you need to record a data breach, policy breach, safeguarding process issue, access concern, or other compliance event that needs an audit trail.

Before you start... follow your organisation incident and breach process. Some events may have legal, contractual, safeguarding, or notification requirements. If you are unsure, record the event promptly and escalate to the responsible compliance owner.

The TuitionFlow compliance dashboard showing breach, audit, GDPR, checks, and document areas.

Use Compliance to record breach and audit activity in a controlled place.

What counts as breach or audit activity

Examples include personal data sent to the wrong person, unauthorised access, lost documents, accidental disclosure, missed consent process, safeguarding process failure, incorrect role permissions, or repeated policy non-compliance. Audit activity can also include planned reviews, access checks, document reviews, and closure notes.

Record facts first. Do not wait until every detail is known before creating a record. You can update the record as investigation progresses.

Step 1: Create the initial record

Record the date, reporter, type of incident, affected area, people involved, initial facts, and immediate action taken. Keep the wording factual and avoid blame.

Expected outcome: the organisation has a dated record that a potential breach or audit item exists and has an owner.

Step 2: Assign ownership

Assign the record to the person responsible for review. That may be an owner, compliance lead, safeguarding lead, data protection owner, or branch manager. Add a due date or review date if the issue needs follow-up.

Step 3: Investigate and update

Add updates as facts become clear. Record what was checked, what was corrected, who was notified, and whether any external reporting is required. Avoid copying unnecessary personal data into updates.

The TuitionFlow settings area where access and organisation controls may need review after an audit event.

Some breach or audit findings require settings, permissions, or process changes.

Step 4: Close with outcome and prevention

When the issue is resolved, record the outcome, date closed, owner, and prevention action. Prevention might include permission changes, staff guidance, form updates, process changes, or additional review.

Common mistakes

  • Waiting too long to record. Create an initial record while facts are fresh.

  • Using emotional or blaming language. Keep audit records factual.

  • Forgetting prevention action. Closure should explain how recurrence will be reduced.

  • Storing breach detail in general notes. Use the restricted compliance area.

Troubleshooting

The incident affects multiple records: link or reference each area, but keep the main breach record centralised.

You are unsure whether it is reportable: escalate to the responsible owner and record that review is needed.

A user had access they should not have had: correct permissions, record the time period, and review whether any data was accessed.

Audit review rhythm

Review open breach and audit items regularly. Look for overdue actions, repeated causes, permission patterns, and process gaps. Use the review to improve controls, not only to close records.

Containment examples

Containment might include correcting permissions, recalling a message, removing a shared file, pausing an integration, notifying an owner, or asking users not to access a record while it is reviewed. Record what happened and when.

Learning from incidents

After closure, look for root causes. Was the issue caused by unclear permissions, rushed admin work, duplicate records, missing training, confusing forms, or weak handoff? Add a prevention action that addresses the cause, not only the symptom.

Reporting and escalation

Some incidents may need external reporting, parent notification, staff follow-up, or legal review. Do not decide this alone unless you are the responsible owner. Record that escalation was considered and who made the decision.

Owner sign-off

For serious incidents, ask the responsible owner to sign off closure before marking the record complete. This makes accountability clear and reduces the risk of closing an item before prevention work is done.

Evidence handling

If evidence is needed, store it in the approved compliance document area and keep filenames factual. Keep access narrow, and avoid sending evidence through ordinary messages unless your process specifically allows it. Do not scatter screenshots, exports, or message copies across personal folders. Limit access to people involved in review and resolution.

Follow-up review

Revisit serious incidents after the prevention action has been in place for a while. Confirm the change actually reduced risk and did not create a new operational problem.

Next actions

After recording a breach or audit item, assign an owner, set a review date, complete immediate containment actions, and document the final outcome in the compliance record.

Did this answer your question?