Artifact GuideUSRisk Assessments Cybersecurity Audits and ADMT
US CPRA Risk Assessments Cybersecurity Audits and ADMT
Run three separate tests for section 7150 risk assessments, section 7120 cybersecurity audits, and Article 11 ADMT rights; a yes under one test does not answer either of the others.
The final CPPA regulations became effective January 1, 2026 and use different activity, entity, decision, transition, evidence, and consumer-rights rules.
processes personal information and uses computation to replace or substantially replace human decisionmaking. exists only when the reviewer knows how to interpret and use the output, analyzes it with other relevant information, and has authority to make or change the decision. The final CPPA regulations governing ADMT, risk assessments, and cybersecurity audits became effective January 1, 2026, but each article has a separate trigger and transition rule.
1
Section 1
Who must follow the US CPRA risk assessment, cybersecurity audit, and ADMT rules?
Risk assessments cover the six section 7150 processing categories and occur before new covered processing starts. The categories include sale or sharing, sensitive-information processing, covered ADMT and profiling, sensitive-location inference, and specified training. A narrow sensitive-information exception covers only listed employee and independent-contractor administration purposes. Covered processing begun before January 1, 2026 must be assessed by December 31, 2027.
Cybersecurity audits use the separate section 7120 entity test: at least 50 percent of preceding-year revenue from sale or sharing, or annual gross revenue above $26,625,000 effective January 1, 2025 plus processing of at least 250,000 consumers or households or sensitive information of at least 50,000 consumers. First reports are due April 1, 2028, 2029, or 2030 under the revenue-tier phase-in.
Article 11 applies when ADMT makes a : provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services. Ordinary hosting, networking, storage, security tools, spellchecking, calculators, databases, and spreadsheets are excluded only when they do not replace human decisionmaking.
Before covered ADMT use, give a plain-language pre-use notice describing the specific purpose, opt-out or appeal route, access right, non-retaliation, categories affecting output, output type and use, and, where an opt-out must be offered, the alternative decision process. Businesses using covered ADMT before January 1, 2027 must comply by that date; uses beginning on or after that date must comply whenever used.
Risk assessment: identify the activity and exact trigger, document required operations, benefits, negative impacts and safeguards, refuse processing when risks outweigh benefits, review at least every three years, and update within 45 days after a material change.
Cybersecurity audit: calculate entity scope, appoint a qualified and impartial auditor, test the required cybersecurity-program areas, remediate or document findings, and obtain the executive certification.
ADMT: identify the and human role, give the pre-use notice, provide access, and implement the opt-out unless a section 7221 exception applies. The human-appeal exception requires a reviewer who knows how to interpret and use the output, considers relevant information and the consumer's submission, and can overturn the decision.
Link the three records when one system triggers more than one article, but preserve separate trigger conclusions, owners, deadlines, evidence, and consumer-facing duties.
What fields should the Risk Assessments Cybersecurity Audits and ADMT template capture?
The privacy, security, product, and decision owner may share one intake, but they must record three separate determinations. A yes for one article does not establish scope for either of the others.
Entity and activity: business, product, system, consumers, data, purpose, recipients, launch date, revenue and volume evidence, and owners.
Risk assessment: section 7150 trigger and exception, report, safeguards, balance, approval, three-year review, 45-day material-change update, and summary submission.
Cybersecurity audit: section 7120 calculation, audit period, auditor and independence, tests, findings, remediation, certification, and submission.
ADMT: significant-decision category, human-involvement test, purpose, inputs, output and use, pre-use notice, access response, opt-out or appeal path, exception evidence, downstream instructions, and January 1, 2027 transition.
How should teams review and improve the Risk Assessments Cybersecurity Audits and ADMT workflow?
Review intake when a model, decision, human-review process, data source, use, recipient, entity threshold, or safeguard changes. Sample live outcomes and consumer requests; policy text alone cannot show that an ADMT opt-out, risk safeguard, or audit control operates as described.
Reopen the risk assessment within the 45-day material-change window and preserve the next three-year review date; these are different triggers.
Recalculate section 7120 every year from finance and data-volume evidence, and test auditor independence before each annual audit.
For ADMT, test notice delivery before use, response accuracy, the 15-business-day opt-out completion deadline, downstream instructions, and whether any claimed exception still applies.
Keep binding CPPA duties separate from NIST control or assessment publications, which can organize evidence but do not replace California scope, notice, rights, reports, or deadlines.
Sections 7120-7124, 7150-7157, and 7200-7222 support the annual scope check, risk-assessment update, ADMT notice, 15-business-day opt-out, and exception review.
The CPPA regulations page is the official rulemaking hub for CCPA updates covering cybersecurity audits, risk assessments, ADMT, and insurance regulations.