Start with an information audit and interviews with the teams that design, buy, operate, secure, and retire processing. Compare the result with system inventories, contracts, notices, retention schedules, transfer records, DPIAs, incident records, and actual access paths.
Review on material change and on a risk-based schedule. Correct the record when purposes, systems, recipients, countries, retention, roles, security measures, or data categories change; preserve enough history to explain when and why the entry changed.