# ISO/IEC 27701 Lead Implementer interview scorecard

Candidate: ______  Interviewer: ______  Date: ______

| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | What is a privacy information management system? | A management system for protecting personal data, with roles, policies, risk assessment, controls and continual improvement. | |
| 2 | How would our PIMS relate to our ISMS? | They share structure and many controls. Check which edition of ISO/IEC 27701 your certification body audits against, since that shapes the link. | |
| 3 | Are we a PII controller, a processor, or both? | Decided per processing activity, because the controls differ for each role. | |
| 4 | How would you map the PIMS to the GDPR? | Map each control to the articles it supports and show where the law asks for more. | |
| 5 | How do you handle personal data in contracts with processors? | Required terms, due diligence before signing, and checks during the contract. | |
| 6 | How do you build privacy impact assessment into the PIMS? | Clear triggers, a standard method, and results that feed risk treatment. | |
| 7 | How does the PIMS handle data subject requests? | Intake, verification, deadlines, records and measures. | |
| 8 | How do you prepare for certification? | Documents ready, evidence the PIMS runs, and an internal audit and management review done first. | |

Source: https://credentialpress.com/guides/iso-27701-lead-implementer-interview-questions
