Working Draft — content version 1.4.0 · review package 1.2 · not approved content
SRCF / framework / domain I / I.8
Domain I · Area I-CA3 · Information protection, human accountability and tool governance

I.8Protect data, privacy, security and intellectual property in digital and AI tools

Working Draft version 1.1

Purpose and scope

This unit covers the capability to determine what reporting information may be entered into, processed by, retrieved from or shared through digital and AI tools and to apply proportionate privacy, confidentiality, security, access, retention, data-location, vendor, intellectual-property, copyright and incident controls. It includes public, internal, confidential, personal, privileged, market-sensitive and proprietary information and generated or uploaded content.

Applied competency statement
Can classify and protect reporting information used in digital and AI tools through authorised data-use, access, transfer, retention, security, vendor, rights and incident controls.
Boundary and escalation
This unit owns digital and AI tool data flows, provider and connector access, retention, security and intellectual-property controls. H.4 owns general professional information handling, G.9 owns public disclosure treatment and I.1 owns broader vendor and tool selection. Legal, privacy, security, market-conduct and rights decisions require qualified owners.
Key quality risks
Confidential, personal, privileged or market-sensitive information entered into public or unauthorised tools; model training or provider reuse not understood; excessive user or administrator access; shared accounts; data stored or transferred to unapproved locations; retrieval or logs exposing sensitive content; prompts and outputs retained longer than intended; copyright or licensed standards text uploaded or generated outside permitted use; provider or plugin access not assessed; secrets included in prompts; prompt injection causing data disclosure; and incidents not contained, reported or linked to affected reporting work.
Required knowledge · 6
I.8-K01
Understands public, internal, confidential, personal, privileged, proprietary, licensed, security-sensitive, market-sensitive and restricted information and the need for contextual classification.
Knowledge Type: Information classification · Normative Weight: Core
I.8-K02
Understands prompts, uploaded files, retrieved context, embeddings, logs, outputs, feedback, model training, provider retention, plugins, connectors, agents and subprocessors.
Knowledge Type: AI and tool data flows · Normative Weight: Core
I.8-K03
Understands authentication, role and privilege, shared accounts, secrets, encryption, secure transfer, environment separation, logging, monitoring and incident containment at a reporting-user level.
Knowledge Type: Access and security · Normative Weight: Core
I.8-K04
Understands purpose, minimum necessary use, consent or authority where applicable, data minimisation, location, retention, deletion, subject rights and vendor or cross-border considerations.
Knowledge Type: Privacy and retention · Normative Weight: Core
I.8-K05
Understands copyright, database and licence restrictions, confidential methods, standards content, generated output, attribution, permitted use and the need for rights review.
Knowledge Type: Intellectual property and rights · Normative Weight: Core
I.8-K06
Understands suspected leakage, unauthorised access, malicious content, prompt injection, provider incident, evidence preservation, notification and the boundary with specialist security and legal response.
Knowledge Type: Incident and governance boundary · Normative Weight: Core
Applied skills · 5
I.8-S01
Classify data, documents, prompts, context and outputs and determine authorised digital and AI uses, prohibited inputs and required controls.
Skill Type: Core applied capability · Observable Output or Result: Digital and AI data-classification and permitted-use rules
I.8-S02
Evaluate tool settings, accounts, access, data flow, provider use, retention, location, subprocessors, plugins, export, deletion and rights conditions.
Skill Type: Tool and vendor assessment · Observable Output or Result: Tool access, vendor, retention and rights assessment
I.8-S03
Define approved environments, user roles, secure transfer, redaction, anonymisation, logging, retention, deletion and external-sharing procedures.
Skill Type: Protected workflow design · Observable Output or Result: Protected digital and AI use procedure
I.8-S04
Assess whether source, standards, proprietary, licensed or generated content may be uploaded, transformed, retained, reproduced and shared and obtain authorised review.
Skill Type: Rights and content control · Observable Output or Result: Digital content and intellectual-property record
I.8-S05
Stop and contain suspected leakage or misuse, preserve evidence and coordinate authorised notification, remediation, output review and affected reporting correction.
Skill Type: Incident response · Observable Output or Result: Digital or AI information incident and remediation record
Professional behaviours · 3
I.8-B01
Does not enter or share sensitive information with a digital or AI tool merely because it is convenient or may improve the output.
Behaviour Type: Data-minimisation discipline · Non-compensable Requirement: No
I.8-B02
Does not bypass access, licence, retention or approved-environment restrictions to meet a reporting deadline.
Behaviour Type: Access and rights integrity · Non-compensable Requirement: No
I.8-B03
Does not conceal or informally resolve a suspected digital or AI information incident outside the authorised security, legal and reporting process.
Behaviour Type: Incident transparency · Non-compensable Requirement: No
Typical tasks · 4
I.8-T01
Inventory the reporting information, users, tools, connectors, vendors, data flows, sensitivity, rights and intended uses.
Primary Output Link: I.8-O01
I.8-T02
Assess accounts, access, provider terms, retention, location, training or reuse, subprocessors, plugins, export, deletion and rights.
Primary Output Link: I.8-O02
I.8-T03
Design and operate protected use, redaction, transfer, logging, retention, deletion and content-rights procedures.
Primary Output Link: I.8-O04
I.8-T04
Contain and escalate incidents, preserve evidence and coordinate notification, remediation and review of affected data, outputs and reporting.
Primary Output Link: I.8-O03
Expected outputs · 4
I.8-O01
Digital and AI data-classification and permitted-use rules
Output Type: Professional work product
I.8-O02
Tool access, vendor, retention and rights assessment
Output Type: Professional work product
I.8-O03
Digital or AI information incident and remediation record
Output Type: Professional work product
I.8-O04
Protected digital and AI use procedure
Output Type: Professional work product
Proficiency indicators
Level 1 · Foundation
I.8-L1-01
Can follow approved data-classification and tool-use rules, maintain access records and identify obvious prohibited input, account or sharing risks.
Indicator Dimension: Task execution
I.8-L1-02
Can stop use and escalate privacy, security, privilege, market-sensitive or rights questions before entering or sharing information.
Indicator Dimension: Quality, judgement and accountability
Level 2 · Practitioner
I.8-L2-01
Can independently design and operate protected digital and AI use for a moderately complex reporting workstream and assess routine vendor and rights conditions.
Indicator Dimension: Task execution
I.8-L2-02
Can resolve routine access, redaction, retention and permitted-use issues and coordinate incident response and reporting review.
Indicator Dimension: Quality, judgement and accountability
Level 3 · Advanced Practitioner
I.8-L3-01
Can design or critically review enterprise digital and AI information-protection governance across complex groups, vendors, jurisdictions and integrations.
Indicator Dimension: Method design and review
I.8-L3-02
Can challenge unsafe data use or provider conditions, coordinate the resolution of significant privacy, security and rights conflicts with qualified owners, and advise governance bodies on restriction, remediation, notification and residual risk.
Indicator Dimension: Leadership and governance
Illustrative evidence · 6
I.8-E01
Digital and AI data-classification and permitted-use rules.
Evidence Type: Work product
I.8-E02
Tool access, vendor, retention and rights assessment.
Evidence Type: Work product
I.8-E03
Digital or AI information incident and remediation record.
Evidence Type: Work product
I.8-E04
Classification, access, term, consent or authority, redaction, transfer, log, retention, deletion, incident and correction trail.
Evidence Type: Process evidence
I.8-E05
Documented security, privacy, legal, procurement, records, market-conduct, quality or management review and the practitioner's response.
Evidence Type: Review evidence
I.8-E06
Observed response to an unsafe data-input, prompt-injection or information-leakage scenario.
Evidence Type: Observed performance
Assessment · 3
I.8-A-L1
Data-classification exercise, tool-use scenario and situational judgement
Classification and minimum necessary use; access, rights and provider awareness; stop-use and escalation.
I.8-A-L2
Integrated digital-information case and professional memorandum
Data-flow and vendor assessment; privacy, security and rights controls; incident and reporting response.
I.8-A-L3
Complex data-and-rights governance case, portfolio and oral defence
Method design; data, provider and rights judgement; restriction and incident governance; oral defence.
Relationships · 9
FromToTypeRationale
D.7I.8Professional conduct and collaboration linkageExternal tool and provider access must protect privacy, confidentiality and information security.
H.4I.8Digital and technology linkageTechnology-specific privacy, confidentiality and security controls support professional information handling.
I.4I.8Professional conduct and collaboration linkageResearch prompts, sources and knowledge systems should comply with confidentiality, rights and permitted-use controls.
I.7I.8Professional conduct and collaboration linkageData, privacy, security, prompt-injection and vendor risks form part of the AI use-case assessment.
I.8H.4Professional conduct and collaboration linkageDigital and AI information controls implement confidentiality, privacy and sensitive-information responsibilities.
I.8E.9Evidence and traceability linkageMetadata, lineage, retention and authoritative records support controlled digital and AI use.
I.8D.7Governance and role linkageVendor, connector and subcontractor data and rights risks should be managed through third-party governance.
I.8I.1Digital and technology linkageTool selection should consider data flow, provider retention, access, rights and security conditions.
I.8I.9Governance and role linkagePermitted data use, incidents, exceptions and vendor risk require enterprise ownership and monitoring.
Role profiles for this unit
RoleTarget levelRelevanceEvidence expectation
Corporate Sustainability Reporting Practitioner PractitionerRequired?A case or work sample demonstrating independent performance, documented judgement and a reviewable professional output.
Sustainability Reporting Manager or Lead Advanced PractitionerRole-defining?A complex case or verified portfolio, supplemented by oral or observed defence, demonstrating method design, challenge and governance capability.
Sustainability Reporting Adviser or Consultant Advanced PractitionerRole-defining?A complex case or verified portfolio, supplemented by oral or observed defence, demonstrating method design, challenge and governance capability.
Sustainability Data, Systems and Controls Specialist Advanced PractitionerRole-defining?A complex case or verified portfolio, supplemented by oral or observed defence, demonstrating method design, challenge and governance capability.
Assurance Readiness and Reporting Quality Specialist Advanced PractitionerRole-defining?A complex case or verified portfolio, supplemented by oral or observed defence, demonstrating method design, challenge and governance capability.
Investor, Capital Markets and Ratings Disclosure Specialist Advanced PractitionerRole-defining?A complex case or verified portfolio, supplemented by oral or observed defence, demonstrating method design, challenge and governance capability.