Skip to main content

How do I select the correct Organisation Type in DSPT, and when is an audit required?

Written by Dominic Horwood

How do I select the correct Organisation Type in DSPT, and when is an audit required?

When using the Data Security and Protection Toolkit (DSPT) platform, it is essential to select the correct Organisation Type to ensure compliance and determine whether an independent external audit is required. Below is a guide to help you navigate this process.

Overview of Organisation Types in DSPT

The DSPT platform requires organizations to specify their Organisation Type under the "Manage Organisation" section. This selection impacts the number of questions you need to answer and whether an audit is necessary.

Criteria for IT Suppliers

If your organization is categorized as an "IT Supplier," the audit requirement depends on whether you meet the following thresholds:

  • Staff Size: 50 or more employees

  • Turnover: £10 million or more annually

Organizations meeting these thresholds must undergo an independent external audit. If your organization does not meet these criteria, you should select "Other" as your Organisation Type.

Implications of Selecting "Other"

Choosing "Other" as your Organisation Type has the following benefits:

  • Reduced Questions: The number of questions in the DSPT is significantly reduced.

  • No Audit Requirement: Organizations selecting "Other" are not required to complete an independent external audit.

Audit Requirements

An independent external audit is mandatory only for Category 1 organizations or IT Suppliers that meet the specified thresholds (50+ staff or £10m turnover). For all other organizations, including those selecting "Other," an audit is not required. By carefully selecting the appropriate Organisation Type, you can streamline your DSPT submission process and ensure compliance with the platform's requirements.

Did this answer your question?