How do I select the correct Organisation Type in DSPT, and when is an audit required?
When using the Data Security and Protection Toolkit (DSPT) platform, it is essential to select the correct Organisation Type to ensure compliance and determine whether an independent external audit is required. Below is a guide to help you navigate this process.
Overview of Organisation Types in DSPT
The DSPT platform requires organizations to specify their Organisation Type under the "Manage Organisation" section. This selection impacts the number of questions you need to answer and whether an audit is necessary.
Criteria for IT Suppliers
If your organization is categorized as an "IT Supplier," the audit requirement depends on whether you meet the following thresholds:
Staff Size: 50 or more employees
Turnover: £10 million or more annually
Organizations meeting these thresholds must undergo an independent external audit. If your organization does not meet these criteria, you should select "Other" as your Organisation Type.
Implications of Selecting "Other"
Choosing "Other" as your Organisation Type has the following benefits:
Reduced Questions: The number of questions in the DSPT is significantly reduced.
No Audit Requirement: Organizations selecting "Other" are not required to complete an independent external audit.
Audit Requirements
An independent external audit is mandatory only for Category 1 organizations or IT Suppliers that meet the specified thresholds (50+ staff or £10m turnover). For all other organizations, including those selecting "Other," an audit is not required. By carefully selecting the appropriate Organisation Type, you can streamline your DSPT submission process and ensure compliance with the platform's requirements.
