Every store has a named owner and a task
The inventory phase assigns each data store to its owner with a due date. Owners confirm the level and the sample results themselves, so the review does not depend on one person chasing a spreadsheet.
A classification scheme is only useful if people apply it and the controls downstream respect it. Data loss prevention rules, encryption, sharing settings and access reviews all key off the level a piece of information carries. When the labels are wrong or missing, those controls protect the wrong things. This free data classification review checklist is for information security managers, data protection officers and information governance leads who run the periodic check of the scheme and how well it is applied: once a year as a baseline, and again after a merger, a new core system or a change in the law. Seven phases cover the scheme itself, the data inventory and its owners, sample checks of labelled and unlabelled content, label coverage and auto-labelling, handling rules and regulated data, alignment with DLP, access and training, and the exceptions and sign-off that close the cycle.
Classification ranks information by the harm its loss or misuse would cause, then attaches handling rules to each rank. ISO/IEC 27001:2022 Annex A 5.12 asks for information to be classified by its confidentiality, integrity and availability needs and the requirements of interested parties, and 5.13 asks for labelling procedures that follow the scheme. Commercial schemes usually settle on four levels, often called Public, Internal, Confidential and Restricted, though the names vary. Government schemes differ. The UK Government Security Classifications Policy, updated in June 2023, has three tiers (OFFICIAL, SECRET and TOP SECRET), with -SENSITIVE as an additional marking on OFFICIAL information rather than a fourth tier. US federal agencies categorise information and systems as low, moderate or high impact under FIPS 199. If you hold government or defence contracts, your scheme has to map to theirs.
Schemes drift for predictable reasons. New kinds of data arrive that nobody placed in a level. A default label of Internal quietly becomes the label for everything. Staff over-classify to be safe, and when everything is Confidential the word stops meaning anything. Under-classification is worse, because it lets restricted data travel through channels built for internal memos. A review finds these patterns while they are still small. It is a different exercise from a retention review, which asks how long each record class is kept and how it is destroyed. The two can share an inventory, but they answer different questions.
Holds: the levels, a definition and examples for each, and the handling rules that go with them.
Owner: the information security manager or CISO, approved by senior management.
Changes: when the business, the law or a customer contract changes what counts as sensitive.
Asks: does the scheme still fit, is it applied correctly, and do the controls follow the labels?
Cadence: yearly, plus after a merger, a new core system, a new regulation or a data incident.
Produces: sample results, an updated handling matrix, an exceptions register and signed approval.
Asks: what has passed its retention period, what is on legal hold, and what can be destroyed.
Cadence: yearly, or quarterly for high-volume systems.
Produces: a disposal log and deletion evidence.
Run both from the same data inventory. The retention cycle lives in the Data Retention & Disposal Review Checklist; this page stays on sensitivity, labels and handling.
Seven phases take one review cycle from the scheme to signed approval. The auto-labelling and regulated data steps appear only when Phase 1 says they apply.
Owned by the information security manager or DPO. The Phase 1 answers on labelling tools and regulated data decide which tasks appear in Phases 4 and 5.
Sample sizes are risk-based: larger for stores holding Confidential or Restricted data. Results go in a table inside the task.
Appears only when Phase 1 records that a labelling tool is deployed. Assigned to the administrator of that tool, with the information security manager reviewing.
The regulated data tasks appear only for the categories Phase 1 records as held. Legal or the DPO confirms the legal mapping.
Sign-off is an approval task for the CISO or senior information risk owner. The checklist does not close until it is approved.
Few frameworks say how often to review a classification scheme. CIS Controls v8.1 is the exception: safeguard 3.7 asks for the scheme to be reviewed and updated annually or when significant enterprise changes occur, and 3.2 asks for the data inventory to be reviewed at least annually, prioritising sensitive data. The table maps the requirements this review most often has to meet to the phase that produces the evidence.
| Framework | Reference | What it expects | Evidenced in |
|---|---|---|---|
| ISO/IEC 27001:2022 Annex A | 5.12, 5.13 | Information classified by confidentiality, integrity, availability and interested party requirements; labelling procedures that follow the scheme | Phases 1, 3–4 |
| ISO/IEC 27001:2022 Annex A | 5.9, 5.10 | An inventory of information and associated assets with owners; rules for acceptable use and handling | Phases 2, 5–6 |
| CIS Controls v8.1 | 3.2, 3.7 | A data inventory and a classification scheme, each reviewed and updated at least annually | Phases 1–2 |
| NIST FIPS 199, SP 800-60 | Security categorisation | Information and systems categorised as low, moderate or high impact for confidentiality, integrity and availability; information types mapped to provisional impact levels | Phases 1–2 |
| GDPR and UK GDPR | Arts. 9, 10, 30 | Records of processing that describe categories of personal data; extra conditions for special category and criminal offence data | Phases 2, 5 |
| PCI DSS v4.0.1 | 9.4.2 | All media with cardholder data classified in accordance with the sensitivity of the data | Phase 5 |
| SOC 2 Trust Services Criteria | C1.1 | Confidential information identified and maintained to meet the entity’s confidentiality objectives | Phases 2, 6 |
Treat the table as a starting point, not legal or audit advice. Your auditor or certification body decides what counts as sufficient evidence for your scope, and counsel should confirm which data protection rules apply. The GDPR does not use the word classification, but you cannot keep accurate Article 30 records or apply Article 32 security appropriate to the risk without knowing which data is sensitive.
One revision is still in progress. NIST published an initial working draft of SP 800-60 Revision 2 in January 2024 to update the information types and bring privacy into categorisation, and in April 2026 still listed it as an upcoming publication. Volumes 1 and 2 of Revision 1 remain the published guidance, so check the status before citing the draft.
The inventory phase assigns each data store to its owner with a due date. Owners confirm the level and the sample results themselves, so the review does not depend on one person chasing a spreadsheet.
Conditional logic driven by the Phase 1 answers adds the auto-labelling tasks only where a labelling tool exists, and the cardholder, health or special category tasks only for data you actually hold. A small organisation gets a short review.
Sample tables, coverage reports, DLP summaries and training records are attached to the task they support. The audit trail records who completed each step and when, and the final approval holds the sign-off.
CheckFlow is not a labelling, discovery or DLP tool. It runs the human side of classification around those tools: who owns each store, who checked the sample, what was decided and who approved it. CheckFlow for compliance checklists shows how a yearly review like this sits alongside your other recurring controls, and the ISO 27001 checklist guide explains where classification fits in an ISMS.
Classification feeds other reviews. Pair it with the GDPR Compliance Audit Checklist for records of processing and lawful bases, the Data Retention & Disposal Review Checklist for how long each level is kept, and the User Access Review Checklist to confirm who can reach the Restricted stores.
It is a scheduled check that your classification scheme still fits the business and that people and systems apply it correctly. The review confirms the levels and handling rules, checks that every data store has an owner and an assigned level, samples labelled and unlabelled content for accuracy, and confirms that controls such as DLP, encryption and access rules follow the labels. It ends with an updated scheme, a list of exceptions and management sign-off.
At least once a year, and again after significant change. CIS Controls v8.1 safeguard 3.7 asks for the classification scheme to be reviewed and updated annually or when significant enterprise changes occur. Typical triggers for an extra review are a merger, a new core system, a new regulation or contract requirement, and an incident involving mislabelled data.
Most commercial schemes use four levels, commonly Public, Internal, Confidential and Restricted, though some call the top level Highly Confidential or Secret. Public data can be released freely; Internal is for staff only; Confidential would cause harm if disclosed; Restricted would cause serious harm and gets the tightest controls. Government schemes differ: the UK uses OFFICIAL, SECRET and TOP SECRET, and US federal systems are categorised as low, moderate or high impact under FIPS 199. Fewer levels are easier for staff to apply correctly.
Classification is the decision about how sensitive information is. Labelling is how that decision is recorded on the information so people and systems can see it: a header, a watermark, a metadata tag or a sensitivity label applied by a tool such as Microsoft Purview. ISO/IEC 27001:2022 treats them as two controls, 5.12 for classification and 5.13 for labelling. A review checks both, because correct decisions that are never labelled cannot drive DLP or encryption.
The data owner, usually the business manager accountable for a system or data set, decides its level. People who create documents and emails label them in line with the scheme. The information security manager or CISO owns the scheme itself and runs the review, and the DPO advises on personal data. Senior management approves the scheme and accepts the exceptions.
Not by name. The GDPR requires records of processing that describe the categories of personal data you hold (Article 30), extra conditions for special category data (Article 9) and security appropriate to the risk (Article 32). In practice those duties are hard to meet without knowing which data is sensitive and where it is, which is what a classification scheme provides. Confirm with counsel how the rules apply to your organisation.
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.