High-risk processing assessment
DPIA Risk Register
Illustrative DPIA risk register for the KYB architecture. Risk scores use Likelihood × Impact (1–5). Residual values are targets after mitigation and require control testing before acceptance.
| ID | Risk scenario | Area | L | I | Inherent | Primary mitigation | Residual | Level |
|---|---|---|---|---|---|---|---|---|
| D01 | Incorrect OCR extraction causes wrong identity/business record | Document AI | 3 | 4 | 12 | Field confidence, cross-document match, HITL | 6 | Medium |
| D02 | Tampered document not detected | Document AI | 3 | 5 | 15 | Attack-class testing, secondary checks, manual review | 8 | Medium |
| D03 | Authentic document falsely flagged as tampered | Document AI | 3 | 4 | 12 | Calibrated threshold, reviewer override, evidence view | 6 | Medium |
| D04 | Raw legal document breach | Document storage | 3 | 5 | 15 | Private store, encryption, RBAC/PAM, short retention | 6 | Medium |
| D05 | Biometric-like image features reused outside purpose | Vision | 2 | 5 | 10 | Purpose restriction, no training, isolated processing | 4 | Low |
| D06 | Website crawler collects unnecessary personal data | Website | 4 | 3 | 12 | Selector/minimization policy, masking, evidence-only retention | 4 | Low |
| D07 | Website ToS / robots policy violation | Website | 3 | 4 | 12 | Connector policy gate and legal approval | 4 | Low |
| D08 | Website LOB misclassification harms merchant | Website | 3 | 4 | 12 | Explainability, confidence, appeal/EDD, benchmark | 6 | Medium |
| D09 | Prohibited-category false positive | Website | 3 | 5 | 15 | High threshold, corroboration, manual decision | 6 | Medium |
| D10 | Stale WHOIS/domain data drives wrong risk | Website | 3 | 3 | 9 | Freshness TTL, timestamp, re-query | 3 | Low |
| D11 | Wrong Google Business profile matched | Google Review | 3 | 4 | 12 | Entity match using name/address/domain/phone | 5 | Medium |
| D12 | Negative review sentiment over-weighted | Google Review | 3 | 4 | 12 | Weight caps, themes + evidence, human context | 5 | Medium |
| D13 | Reviewer personal data collected excessively | Google Review | 3 | 3 | 9 | Pseudonymization/minimization | 3 | Low |
| D14 | Fake-review model falsely labels genuine reviews | Google Review | 3 | 3 | 9 | Signal-only use, calibrated thresholds | 4 | Low |
| D15 | Adverse-media hit matched to wrong person/company | Adverse Media | 4 | 5 | 20 | Entity resolution, disambiguators, mandatory review | 8 | Medium |
| D16 | Allegation treated as proven fact | Adverse Media | 3 | 5 | 15 | Status taxonomy, source/date context, reviewer guidance | 6 | Medium |
| D17 | Duplicate/syndicated articles inflate risk | Adverse Media | 4 | 3 | 12 | Deduplication and event clustering | 4 | Low |
| D18 | Criminal/court data overprocessed | Adverse/EDD | 3 | 5 | 15 | Restricted purpose/access, minimization, strict retention | 6 | Medium |
| D19 | PEP/sanctions false positive due to common name | Screening | 4 | 5 | 20 | Strong identifiers, threshold bands, analyst disposition | 8 | Medium |
| D20 | Domestic list not refreshed promptly | Screening | 2 | 5 | 10 | Update monitoring, source timestamp, fail-safe alerts | 5 | Medium |
| D21 | Social media monitoring becomes open-ended surveillance | Social | 3 | 5 | 15 | Business-only scope, time window, approved accounts | 5 | Medium |
| D22 | Sensitive traits inferred from social content | Social | 2 | 5 | 10 | Prohibited-inference policy, model/output filtering | 4 | Low |
| D23 | Wrong social account matched to merchant | Social | 3 | 4 | 12 | Account entity verification and threshold | 5 | Medium |
| D24 | Sensitive uploaded image exposed to external vendor | Safe Search | 3 | 5 | 15 | Private runtime, no raw logging, DPA/security review | 5 | Medium |
| D25 | Image safe-search false positive blocks legitimate upload | Safe Search | 3 | 3 | 9 | Threshold tuning, retry/manual upload review | 3 | Low |
| D26 | Cross-source profiling exceeds original purpose | Decisioning | 3 | 5 | 15 | Purpose mapping, ROPA, data-flow governance | 6 | Medium |
| D27 | Black-box risk score cannot be explained | Decisioning | 3 | 5 | 15 | Reason codes, module separability, evidence lineage | 5 | Medium |
| D28 | Automated decline without human review | Decisioning | 3 | 5 | 15 | Human-accountability gate / override workflow | 4 | Low |
| D29 | Model bias / language error disproportionately affects cases | AI Models | 3 | 4 | 12 | Slice testing, drift monitoring, reviewer escalation | 6 | Medium |
| D30 | Model drift degrades accuracy silently | AI Models | 3 | 4 | 12 | Monitoring, benchmark reruns, change control | 5 | Medium |
| D31 | Vendor reuses case data for model training | Third Party | 2 | 5 | 10 | Contract prohibition, technical settings, audit right | 4 | Low |
| D32 | Offshore processing occurs without required review | Third Party | 3 | 5 | 15 | Cross-border gate, routing controls, subprocessor inventory | 5 | Medium |
| D33 | Excessive retention increases breach/rights risk | Data Lifecycle | 4 | 4 | 16 | Data-class retention, deletion jobs, audit metrics | 6 | Medium |
| D34 | Deletion fails in cache/index/backup | Data Lifecycle | 3 | 4 | 12 | Deletion propagation test and tombstone tracking | 5 | Medium |
| D35 | Correction request does not propagate to risk score | Rights | 3 | 5 | 15 | Invalidate stale findings, re-run decision, audit | 5 | Medium |
| D36 | Audit logs leak sensitive content | Audit/Security | 3 | 4 | 12 | Structured logs, masking, access controls, no raw payload | 4 | Low |
Mandatory pre-go-live DPIA closure
Production approval should require evidence that high-impact identity matching, automated scoring, sensitive/criminal-data handling, cross-source profiling, large-scale monitoring and new AI technology controls are implemented and residual risks are formally accepted.