---
title: "US CPRA Risk Assessment Template Guide"
canonical_url: "https://www.sorena.io/artifacts/us/california-privacy-rights-act/cpra-risk-assessment-template"
source_url: "https://www.sorena.io/artifacts/us/california-privacy-rights-act/cpra-risk-assessment-template"
author: "Sorena AI"
description: "US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations."
published_at: "2026-05-09"
updated_at: "2026-07-16"
keywords:
  - "US CPRA"
  - "CPRA Risk Assessment Template"
  - "US CPRA Risk Assessment Template"
  - "compliance checklist"
  - "practical guidance"
  - "Compliance"
  - "Regulatory guidance"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# US CPRA Risk Assessment Template Guide

US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.

*Artifact Guide* *US* *CPRA Risk Assessment Template*

## US CPRA CPRA Risk Assessment Template

Use this guide to resolve CPRA Risk Assessment Template under the CCPA as amended by the CPRA, including the trigger, required action, deadline, owner, and evidence.

Apply the cited California statute and regulations to the actual entity, data flow, system, and recipient role; escalate unresolved legal interpretation.

This page explains when a CPRA risk assessment is required and when it must be completed. Under the CPPA regulations, businesses must conduct a risk assessment before starting processing that presents significant risk to consumers' privacy, including selling or sharing personal information, processing sensitive personal information, using ADMT for a significant decision, using automated processing for extensive profiling, and training ADMT or AI in the ways listed in section 7150(b). For processing that started before the effective date and continues afterward, the assessment must be completed within 24 months of the effective date, and the regulations also require ongoing review and updates.

## How should a CPRA Risk Assessment Template workflow run under the US CPRA?

Run the workflow as California privacy triage: threshold, data category, consumer right, opt-out/sensitive-data status, vendor role, required action, evidence, and review. Before you use the template, confirm whether the processing falls into one of the section 7150(b) trigger categories and whether the assessment must be completed before the processing starts or, for legacy processing, within 24 months of the effective date.

- Capture the request, product, role, data flow, jurisdiction, and deadline.
- Check the cited rule and route exceptions before implementation.
- Record the action taken, owner, reviewer, evidence location, and next review date.
- Keep a plain-language output that support, product, legal, security, and compliance teams can all understand.

Sources for this answer:

- [CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology (ADMT), and Insurance Regulations](https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf?ref=sorena.io) - Workflow support from CPPA's final risk-assessment regulations, including when a report is required and what it must document.
- [Security and Privacy Controls for Information Systems and Organizations](https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final?ref=sorena.io) - Workflow support for CPRA Risk Assessment Template.
- [NIST SP 800-53A Rev. 5](https://csrc.nist.gov/pubs/sp/800/53/a/r5/final?ref=sorena.io) - Workflow support for CPRA Risk Assessment Template.

## What fields should the CPRA Risk Assessment Template capture?

A useful template captures business threshold, consumer/data category, request or signal type, vendor role, response deadline, notice/control evidence, and escalation reason.

- Source URL and source quote.
- Entity, product, service, system, data category, and user group.
- Decision result, control action, owner, reviewer, due date, and escalation reason.
- Evidence attachment, approval note, exception note, and review cadence.

Sources for this answer:

- [Security and Privacy Controls for Information Systems and Organizations](https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final?ref=sorena.io) - Template field support for CPRA Risk Assessment Template.
- [NIST SP 800-53A Rev. 5](https://csrc.nist.gov/pubs/sp/800/53/a/r5/final?ref=sorena.io) - Template field support for CPRA Risk Assessment Template.
- [California Consumer Privacy Act Regulations (March 2023)](https://cppa.ca.gov/regulations/consumer_privacy_act.html?ref=sorena.io) - Template field support for CPRA Risk Assessment Template.

## How should teams review and improve the CPRA Risk Assessment Template workflow?

Review the workflow after CPPA rulemaking updates, ad-tech changes, vendor changes, new data categories, consumer complaints, enforcement advisories, or material product changes.

- Track recurring exception categories and update intake questions.
- Remove fields that never affect the decision.
- Add fields when reviews show missing source evidence or unclear ownership.
- Confirm the published page and markdown export show the same cited guidance.

Sources for this answer:

- [CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology (ADMT), and Insurance Regulations](https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf?ref=sorena.io) - Review support from CPPA's risk-assessment submission and update requirements.
- [Security and Privacy Controls for Information Systems and Organizations](https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final?ref=sorena.io) - Review support for CPRA Risk Assessment Template.
- [NIST SP 800-53A Rev. 5](https://csrc.nist.gov/pubs/sp/800/53/a/r5/final?ref=sorena.io) - Review support for CPRA Risk Assessment Template.
- [California Consumer Privacy Act Regulations (March 2023)](https://cppa.ca.gov/regulations/consumer_privacy_act.html?ref=sorena.io) - Review support for CPRA Risk Assessment Template.

*Recommended next step*

*Placement: after the practical guidance*

## Turn US CPRA Risk Assessment Template into assigned work

This US CPRA guide turns CPRA Risk Assessment Template into owners, evidence requests, review checkpoints, and reusable operating records in Sorena.

- [Open Assessment Autopilot for US CPRA](/solutions/assessment.md): Turn CPRA Risk Assessment Template into scoped questions, evidence fields, and review tasks.
- [Review US CPRA source evidence](/solutions/research-copilot.md): Use Research Copilot to answer follow-up questions with cited source material.
- [Talk through implementation](/contact.md): Review scope, evidence, owners, and the next compliance actions with Sorena.

## Primary sources

- [CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology (ADMT), and Insurance Regulations](https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf?ref=sorena.io) - Supports the template's CPRA risk-assessment trigger, report fields, stakeholder inputs, and submission cadence.
  - Quote: "Identify and document in a risk assessment report"
- [Security and Privacy Controls for Information Systems and Organizations](https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final?ref=sorena.io) - Supports this page's CPRA Risk Assessment Template analysis under the US CPRA.
  - Quote: "5 Security and Privacy Controls for Information Systems and Organizations Date Published: September 2020 (includes updates as of"
- [NIST SP 800-53A Rev. 5](https://csrc.nist.gov/pubs/sp/800/53/a/r5/final?ref=sorena.io) - Supports this page's CPRA Risk Assessment Template analysis under the US CPRA.
  - Quote: "assessments of security and privacy controls"
- [California Consumer Privacy Act Regulations (March 2023)](https://cppa.ca.gov/regulations/consumer_privacy_act.html?ref=sorena.io) - Supports this page's CPRA Risk Assessment Template analysis under the US CPRA.
  - Quote: "On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency's regulations and filed"
- [California Privacy Protection Agency FAQ](https://cppa.ca.gov/faq.html?ref=sorena.io) - Supports this page's CPRA Risk Assessment Template analysis under the US CPRA.
  - Quote: "The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"

## Related Topic Guides

- [California CPRA Checklist](/artifacts/us/california-privacy-rights-act/checklist.md): Practical guidance for the California CPRA checklist, with practical decisions, evidence, edge cases, and external source citations.
- [California CPRA FAQ](/artifacts/us/california-privacy-rights-act/faq.md): Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
- [California CPRA penalties and fines Guide](/artifacts/us/california-privacy-rights-act/penalties-and-fines.md): US CPRA guidance for penalties and fines, with practical decisions, evidence, edge cases, and external source citations.
- [California CPRA Requirements Guide](/artifacts/us/california-privacy-rights-act/requirements.md): Practical guidance for California CPRA requirements, with practical decisions, evidence, edge cases, and external source citations.
- [California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide](/artifacts/us/california-privacy-rights-act/risk-assessments-cybersecurity-audits-and-admt.md): California CPRA guidance for risk assessments, cybersecurity audits, and ADMT, with practical decisions, evidence, edge cases, and external source citations.
- [California Data Broker Deletion Workflow Guide](/artifacts/us/california-privacy-rights-act/data-broker-deletion-workflow.md): California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
- [California Data Broker Registry and DROP Guide](/artifacts/us/california-privacy-rights-act/data-broker-registry-and-drop.md): California Delete Act guide to the Data Broker Registry and DROP, with practical decisions, evidence, edge cases, and official source citations.
- [California Delete Act data broker registry and DROP guide](/artifacts/us/california-privacy-rights-act/faq/data-broker-registry-and-drop.md): California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
- [CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation](/artifacts/us/california-privacy-rights-act/faq/enforcement-advisories.md): US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
- [CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ](/artifacts/us/california-privacy-rights-act/faq/gpc.md): US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Applicability Test Guide](/artifacts/us/california-privacy-rights-act/applicability-test.md): Practical guidance for the US CPRA applicability test, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA CCPA vs CPRA Guide](/artifacts/us/california-privacy-rights-act/ccpa-vs-cpra.md): US CPRA guidance for CCPA vs CPRA, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Compliance Guide](/artifacts/us/california-privacy-rights-act/compliance.md): Practical guidance for the US CPRA compliance, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Consumer Rights Workflow Guide](/artifacts/us/california-privacy-rights-act/consumer-rights-workflow.md): US CPRA guidance for Consumer Rights Workflow, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Contract Terms Guide](/artifacts/us/california-privacy-rights-act/contract-terms.md): US CPRA guidance for Contract Terms, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Contracts Contractors and Service Providers Guide](/artifacts/us/california-privacy-rights-act/contracts-contractors-and-service-providers.md): US CPRA guidance for Contracts Contractors and Service Providers, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Correction Rights Guide](/artifacts/us/california-privacy-rights-act/correction-rights.md): US CPRA guidance for Correction Rights, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Cppa Regulations Tracker Guide](/artifacts/us/california-privacy-rights-act/cppa-regulations-tracker.md): US CPRA guidance for Cppa Regulations Tracker, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Cyber Audit Readiness Workflow Guide](/artifacts/us/california-privacy-rights-act/cyber-audit-readiness-workflow.md): US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Deadlines and Compliance Calendar Guide](/artifacts/us/california-privacy-rights-act/deadlines-and-compliance-calendar.md): US CPRA guidance for Deadlines and Compliance Calendar, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA DSAR and Correction Workflow Guide](/artifacts/us/california-privacy-rights-act/dsar-and-correction-workflow.md): US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA GPC Handling Guide](/artifacts/us/california-privacy-rights-act/gpc-handling.md): US CPRA guidance for GPC Handling, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA GPC Handling Workflow Guide](/artifacts/us/california-privacy-rights-act/gpc-handling-workflow.md): US CPRA guidance for GPC Handling Workflow, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Retention Guide](/artifacts/us/california-privacy-rights-act/retention.md): US CPRA guidance for Retention, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Risk Assessment Intake Workflow Guide](/artifacts/us/california-privacy-rights-act/risk-assessment-intake-workflow.md): US CPRA guidance for Risk Assessment Intake Workflow, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Risk Assessments and Cybersecurity Audits Guide](/artifacts/us/california-privacy-rights-act/risk-assessments-and-cybersecurity-audits.md): US CPRA guidance for Risk Assessments and Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Sensitive Personal Information Guide](/artifacts/us/california-privacy-rights-act/sensitive-personal-information.md): US CPRA guidance for Sensitive Personal Information, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Sensitive Personal Information Limits Guide](/artifacts/us/california-privacy-rights-act/sensitive-personal-information-limits.md): US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Sharing and Cross-Context Behavioral Advertising Guide](/artifacts/us/california-privacy-rights-act/sharing-and-cross-context-behavioral-advertising.md): US CPRA guidance for Sharing and Cross-Context Behavioral Advertising, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA vs Colorado Privacy Act Guide](/artifacts/us/california-privacy-rights-act/cpra-vs-colorado-privacy-act.md): US CPRA guidance for CPRA vs Colorado Privacy Act, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA vs Virginia Vcdpa Guide](/artifacts/us/california-privacy-rights-act/cpra-vs-virginia-vcdpa.md): US CPRA guidance for CPRA vs Virginia Vcdpa, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about ADMT under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/admt.md): US CPRA guidance for ADMT, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Contract Terms under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/contract-terms.md): US CPRA guidance for Contract Terms, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Correction Rights under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/correction-rights.md): US CPRA guidance for Correction Rights, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Cybersecurity Audits under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/cybersecurity-audits.md): US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about retention under the California CPRA?](/artifacts/us/california-privacy-rights-act/faq/retention.md): California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
- [What should teams do about Risk Assessments under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/risk-assessments.md): US CPRA guidance for Risk Assessments, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Sensitive Personal Information Limits under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/sensitive-personal-information-limits.md): US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Sharing and Cross-Context Behavioral Advertising under the California CPRA?](/artifacts/us/california-privacy-rights-act/faq/sharing-and-cross-context-behavioral-advertising.md): California CPRA guidance for Sharing and Cross-Context Behavioral Advertising, with practical decisions, evidence, edge cases, and external source citations.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/us/california-privacy-rights-act/cpra-risk-assessment-template.md
