The most common nda inventory mistakes before assessments are incomplete signer populations, unsigned agreements, obsolete templates, weak contractor coverage, missing review evidence, inaccessible records, and inventories that cannot be reconciled to HR or supplier data. To satisfy ISO 27001 control 6.6, an internal auditor should be able to show that confidentiality or non-disclosure agreements are identified, documented, regularly reviewed, and signed by every relevant personnel member and interested party.
How can you find nda inventory mistakes before assessments?
An NDA inventory is not merely a spreadsheet of signed employee documents. It is the evidence trail connecting each role or external party that handles protected information to the correct, current confidentiality obligation. For an external assessor, the central question is straightforward: can the organization demonstrate that its confidentiality obligations reflect its information-protection needs and apply consistently to the people and organizations that need access?
For ISO 27001 practice 6.6, your review should test population completeness, agreement validity, signature status, version control, review frequency, and retrievability. The following NDA inventory errors ahead of an assessment tend to create avoidable nonconformities or extended evidence requests.
Mistake 1: Treating the employee list as the complete signer population
Why it happens: HR is often treated as the sole authoritative source for NDA coverage. That approach captures employees but can omit contractors, temporary workers, interns, board members, consultants, outsourced service desk staff, and suppliers with access to confidential information.
Real-world consequence: An assessor samples a privileged third party from an access review or supplier register and asks for its confidentiality agreement. If that party is absent from the NDA inventory, the organization cannot demonstrate that it identified all relevant interested parties. The issue becomes more serious when the third party has administrative access, receives customer data, or supports incident response.
Concrete remediation: Define the signer population using access and relationship criteria, not employment status. Reconcile the NDA inventory quarterly against HR records, identity directories, contractor rosters, supplier registers, procurement records, and privileged-access groups. Document exclusions, such as suppliers that have no access to organizational or customer information.
| Population | Primary source | Evidence to reconcile | Expected NDA status |
|---|---|---|---|
| Employees | Workday employee export | Hire date, department, termination date | Signed before or at onboarding |
| Contractors | Procurement contractor register | Statement of work, Entra ID account | Signed before access is provisioned |
| Managed service suppliers | Supplier register | MSA, DPA, access approval | Contractual confidentiality clause or NDA |
| Privileged administrators | Microsoft Entra ID PIM report | Eligible and active role assignments | Current agreement linked to identity |
Mistake 2: Recording that an NDA exists without verifying it was signed
Why it happens: Teams track a document as “issued” or “uploaded” and assume that means it is effective. Electronic signature workflows may leave agreements in a pending state, while manually signed files may be incomplete, undated, or signed only by the organization.
Real-world consequence: During sampling, the assessor opens an agreement and finds a missing signer, missing date, or incomplete signature certificate. A record marked “complete” in the inventory is then contradicted by the underlying evidence, reducing confidence in the inventory as a control record.
Concrete remediation: Make signature completion a distinct inventory field and do not classify an agreement as effective until all required signatures are present. Where DocuSign, Adobe Acrobat Sign, or another e-signature platform is used, retain the completion certificate with the executed document. For paper records, scan the fully executed agreement and record the signature date, not just the issue date.
At Northstar Managed Services, a 185-person IT service provider supporting approximately 340 customer environments, the internal audit team compared HaloPSA contractor tickets with DocuSign envelope status. It found nine contractors marked “NDA complete” in a SharePoint register even though their envelopes were still pending. The remediation was not simply to chase nine signatures: the team changed the onboarding workflow so HaloPSA could not move a contractor to “access requested” until the DocuSign status was completed.
Mistake 3: Keeping obsolete NDA templates in circulation
Why it happens: Legal updates an NDA following a new service offering, customer contractual obligation, acquisition, or privacy requirement, but HR, procurement, and department managers keep copies of the old form in local folders. The inventory tracks agreement dates but not template versions.
Real-world consequence: The organization may have signed agreements that do not reflect its current information-protection needs. An assessor may ask how the organization ensures its agreements are reviewed and updated, then identify that recent hires signed a superseded form after the new version was approved.
Concrete remediation: Assign each approved template a version identifier, effective date, owner, and approval record. Keep one controlled source for active templates and archive retired versions as read-only. Add a template-version column to the inventory, then identify who signed a legacy version after the replacement effective date. Legal should determine whether those agreements remain sufficient or require re-execution.
Mistake 4: Assuming supplier contracts automatically cover confidentiality
Why it happens: Procurement teams may record “MSA on file” without confirming that the executed agreement includes confidentiality terms suitable for the relationship. In other cases, the NDA is signed with a parent company while operational access is provided to an affiliate or subcontractor not clearly covered by the agreement.
Real-world consequence: A supplier that processes tickets, monitors systems, stores backups, or provides remote support may have access to sensitive information without demonstrable contractual confidentiality obligations. This is especially visible when supplier access records and the NDA inventory describe different legal entities.
Concrete remediation: Create a supplier confidentiality review field that records the legal entity name, contract reference, confidentiality clause or NDA reference, effective date, and subcontractor coverage. Link it to the supplier register and access approval. For high-risk suppliers, obtain legal confirmation that the agreement covers the actual service entity, relevant personnel, customer information, and permitted subcontractors.
Mistake 5: Failing to define what “regularly reviewed” means
Why it happens: Organizations recognize that agreements should be reviewed but have no review cadence, trigger events, assigned owner, or evidence of completed review. A date in a spreadsheet is often mistaken for a review process.
Real-world consequence: When asked when the NDA inventory was last reviewed, control owners provide an undated export or explain that agreements are reviewed “when needed.” That does not demonstrate the regular review required by ISO 27001 control 6.6.
Concrete remediation: Set a documented cadence, such as an annual inventory review and event-driven review after legal template changes, acquisitions, material service changes, or new data classifications. Preserve evidence: the review scope, reconciled source reports, exceptions, decisions, remediation owner, and closure date. Track a next-review date for both the inventory process and the active template.
Mistake 6: Storing records where they cannot be retrieved during sampling
Why it happens: Signed agreements are distributed across HR folders, email mailboxes, procurement repositories, personnel files, and e-signature portals. The inventory may contain a filename but no stable link, owner, or access-controlled location.
Real-world consequence: The agreement may exist, but the audit team cannot retrieve it promptly or cannot confirm that the version produced is complete. Delayed evidence production can turn a simple sample into an expanded assessment inquiry.
Concrete remediation: Store executed agreements in a controlled repository such as SharePoint, a contract lifecycle management platform, or the HR document system. Record a unique agreement ID and immutable repository link in the inventory. Test retrieval before the assessment by selecting a sample across employees, contractors, suppliers, and terminated personnel.
For example, an IT provider using Microsoft 365 could store executed PDFs in a restricted SharePoint library with retention labels, while keeping a register that includes Agreement ID, Signer Type, Legal Entity, Template Version, Signed Date, Review Date, and Repository URL. Access to the library should be limited to HR, Legal, Procurement, and designated audit personnel.
Mistake 7: Ignoring leavers, role changes, and access changes
Why it happens: NDA tracking is treated as a one-time onboarding activity. Organizations fail to review whether departing personnel remain bound by confidentiality obligations, whether new role responsibilities require updated terms, or whether former contractors retain active accounts.
Real-world consequence: An assessor may compare a leaver report with active privileged accounts and find former staff or contractors still able to access systems. Even if the original NDA survives termination, the organization has not demonstrated effective relationship and access management around confidential information.
Concrete remediation: Connect the NDA inventory to joiner-mover-leaver processes. Ensure offboarding checklists confirm continuing confidentiality obligations where applicable, recover organizational information, and revoke access. Review role changes that introduce access to restricted customer data, source code, security tooling, or privileged administration; determine whether the current agreement remains adequate.
What should you ask during your NDA inventory self-check?
- Can we identify every employee, contractor, supplier, and other interested party that requires a confidentiality obligation?
- Can we reconcile the inventory to HR, procurement, supplier, and privileged-access records?
- Does every sampled record include a complete, dated, executed agreement or a verified contractual confidentiality clause?
- Can we show which approved template version each person or organization accepted?
- Do we have evidence of a regular review cadence and completed review activities?
- Can we retrieve five random agreements within the evidence-response timeframe expected for the assessment?
- Have we tested whether terminated personnel, expired contractors, and supplier access records are handled consistently with the inventory?
Next step: Before the external assessment, perform a documented reconciliation of your NDA inventory against identity, HR, contractor, and supplier populations and close every unexplained exception.