Cross-Border Data Risk Is Identified. It Is Not Actively Managed

Organizations identify cross-border data risks in assessments, document them in records of processing activities, and note them in risk registers.

RCDr. Richard Chingombe · Founder, Verisq·10 min read·Practitioner perspective, not legal advice

Then the risks remain in the register, documented and unaddressed, while the data continues to flow across the same borders under the same conditions that created the identified risk. Identification is necessary. Management is what follows it.

Why This Matters Now

The post-Schrems II compliance era generated substantial investment in cross-border data risk identification. Transfer impact assessments were completed. Records of processing activities were updated. Cross-border data flows were mapped. The output of this work was better documentation of cross-border risk than most organizations had previously maintained.

The management response to that identified risk is where many programs stalled. Completing a TIA that identifies elevated risk in a specific transfer is not the same as addressing that risk. Documenting a cross-border data flow that creates regulatory exposure is not the same as reducing that exposure. The identification phase was completed. The active management phase, which requires ongoing monitoring, risk treatment decisions, technical measures, and continuous governance activity, is where cross-border data governance programs most frequently fall short.

A risk identified and documented but not managed is a risk the organization has chosen to accept by inaction. Active management requires ongoing decisions, ongoing controls, and ongoing monitoring. Documentation is the beginning of that work, not the completion of it.

The Governance Problem Beneath the Surface

Cross-border data risk management requires capabilities that most governance programs were not designed to sustain continuously. Risk identification is a project-based activity: define scope, complete assessment, document findings. Risk management is an ongoing operational discipline: monitor conditions, implement controls, track risk treatment progress, reassess as environments change.

The organizational structures, tools, and processes built for the identification phase of cross-border compliance are not well-suited for the management phase. Privacy teams completed TIAs on deadline. They were not necessarily resourced or structured to maintain ongoing monitoring of the transfer environments those TIAs assessed, to implement the technical measures that TIAs recommended, or to trigger reassessment when third-country legal environments changed.

Risk identification produced a governance artifact. Risk management requires a governance capability that is materially different from what produced the artifact.

See how your own vendors measure up.Security and privacy posture for any vendor, from the outside, free.
Check a vendor's scorecard

What This Actually Means in Enterprise Practice

TIA Findings Go Without Technical Implementation

Transfer impact assessments frequently identify technical measures that would reduce transfer risk: encryption that remains effective against third-country government access, pseudonymization that reduces the identifiability of transferred data, or access controls that limit third-country personnel access to specific data categories. These technical recommendations sit in the TIA documentation and are rarely tracked through to implementation. The assessment found the gap. The governance program did not connect the finding to an accountable owner and a remediation timeline.

Risk Register Entries Are Not Reviewed

Cross-border data risks that are documented in risk registers may remain in those registers for years without substantive review. The risk rating assigned at the time of initial documentation may not reflect subsequent changes in third-country legal environments, vendor practices, data volume, or regulatory enforcement activity. A risk register entry that has not been reviewed in two years is not evidence of active risk management. It is evidence of risk documentation.

Risk registers are governance tools when their contents are actively reviewed, updated, and connected to management actions. When risk register entries are created and not revisited, the register becomes an archive of historical risk identification rather than an active governance instrument.

Vendor Third-Country Processing Changes Are Not Monitored

Vendors that process data in third countries update their infrastructure, add subprocessors in new jurisdictions, and change their data processing practices. These changes may affect the risk profile of transfers that were assessed when the vendor relationship was established. Without ongoing monitoring of vendor processing practices, organizations cannot detect when changes at the vendor level have materially altered the transfer risk that was documented in the original assessment.

Regulatory Environment Changes Are Not Tracked

The legal environments in third countries change. Surveillance legislation is enacted or amended. Court decisions alter the effective protection available to data subjects. Adequacy decisions are challenged or withdrawn. Organizations that completed TIAs in 2022 for transfers to third countries with active legislative changes since then may be relying on risk assessments that no longer accurately reflect the transfer environment.

How Different Teams See This: Where They All Miss

Privacy and LegalCompleted TIAs and documented transfer risks. The project phase is complete. The ongoing management phase requires sustained resourcing and accountability that the project structure did not create.
Risk ManagementMaintaining risk registers that include cross-border transfer risks. May not have the technical expertise to assess changes in third-country legal environments or vendor processing practices.
TPRMConducting vendor risk assessments at defined intervals. Cross-border processing risk may not be a standard component of ongoing vendor monitoring programs.
Information SecurityImplementing security controls for data transfers. TIA-recommended technical measures may not be in scope for security teams that were not involved in the TIA process.

The gap between cross-border risk identification and cross-border risk management is an organizational accountability gap. The identification was done by compliance teams on a project basis. Active management requires ongoing accountability that the project structure did not establish.

Framework Control Reference

The specific control obligations most relevant to this topic across primary frameworks. Use these references in governance discussions, vendor assessments, and audit responses.

GDPR | Article 32Appropriate technical and organizational measures must be implemented and maintained for personal data processing including transfers. Ongoing implementation, not just initial assessment, is required.
GDPR | Article 35(11)Data protection impact assessments must be reviewed when there is a change in the risk represented by processing operations. Third-country legal environment changes trigger reassessment obligations.
EDPB Recommendations 01/2020 | Step 6 ReassessmentSupplementary measures must be reassessed when transfer circumstances change. Organizations have an ongoing obligation to verify that supplementary measures remain effective.
NIST CSF 2.0 | GV.RM-04Risk responses are established and managed to address organizational priorities. Risk documentation without management response does not satisfy risk management framework requirements.
ISO 27001 | Clause 8.3Risk treatment plans must be implemented and the results monitored. Documented risks without treatment plans and implementation monitoring do not meet the standard's requirements.
NIST Privacy Framework | Respond-POrganizations must develop and implement appropriate activities to address detected privacy risk events, including cross-border transfer risks identified through assessment processes.

These controls share a common requirement: the obligation is active, not declarative. Documenting alignment is not the same as demonstrating it.

The Enterprise Reality Gap

The enterprise cross-border risk management reality gap is the space between documented cross-border risk and actively managed cross-border risk. The size of the gap is a function of how many identified risks have received treatment actions, how current risk documentation is relative to changed environmental conditions, and how effectively ongoing monitoring is detecting new risks as they emerge.

Most organizations that completed comprehensive cross-border risk identification programs between 2021 and 2023 are now two to three years past that initial identification work. In that period, third-country legal environments have changed, vendor processing practices have evolved, and new data flows have been established. The gap between the identified risk picture and the current risk reality represents two to three years of unmonitored change.

The cross-border compliance investment of the post-Schrems II period was largely an identification investment. The active management investment, which is the ongoing work that identification was designed to inform, has been deferred in most organizations.

Enterprise Scenario: The Risk That Was Documented and Grew

The setupA European professional services firm completed a comprehensive cross-border transfer program in 2022. TIAs were completed for all significant transfers, risks were documented, and supplementary measures were recommended. The program was presented to the DPO and accepted as meeting post-Schrems II compliance requirements.
Three years laterA vendor that was assessed as medium risk in the original TIA has expanded operations. Their primary infrastructure has shifted to a third country with more aggressive surveillance legislation than was in place at assessment time. The data volume transferred has tripled. The TIA sits in the compliance archive with a 2022 date. The risk it documented has materially increased. Nobody has updated it because no monitoring program was established to detect the changes that would trigger reassessment.

The compliance program was genuine and thorough at the time of completion. The absence of an ongoing management program means the program's output is increasingly disconnected from current reality. The documentation describes the 2022 transfer environment. The organization is operating in a 2025 transfer environment that nobody has assessed.

Industry Signal

European data protection authorities examining cross-border transfer compliance have begun testing the currency of TIA documentation and the presence of ongoing management programs. The examination question is no longer only whether TIAs exist, but whether they are current and whether they are connected to active management of the risks they identify. Organizations that can produce TIAs but cannot demonstrate ongoing risk monitoring and treatment are discovering that the compliance standard has evolved beyond what their 2022 compliance programs addressed.

The regulatory standard for cross-border transfer compliance is shifting from documentation of assessment to evidence of ongoing management. Organizations that treated compliance as a project rather than a program are facing a gap between what they built and what is now expected.

Enabling Capabilities

  • Transfer risk monitoring programs: Defined processes for ongoing monitoring of third-country legal environments, vendor processing practices, and data flow volumes for significant transfers.
  • TIA maintenance processes: Structured reassessment triggers and workflows that update TIA documentation when transfer environments change materially.
  • TPRM with transfer risk focus: Vendor risk management programs that include cross-border processing practices as an ongoing monitoring dimension, not just an onboarding assessment.
  • Regulatory intelligence: Services that monitor third-country legal developments and alert organizations to changes that trigger TIA reassessment obligations.
  • Risk treatment tracking: Governance tools that connect risk identification findings to treatment actions, owners, timelines, and implementation verification.

A Practical Starting Point

Assess the currency of your existing cross-border risk documentation. For each significant transfer in your TIA inventory, identify: when was the TIA last updated, what material changes have occurred at the destination since then, and what treatment actions were recommended in the TIA and which have been implemented.

The currency assessment reveals the gap between documented risk and current risk reality. Prioritize reassessment for transfers where the most significant changes have occurred since the last TIA date, and for transfers where TIA-recommended treatment actions have not been implemented.

Cross-border risk management starts with knowing how current your existing assessment is. The gap between the assessment date and today is the governance work that has not been done.

Questions Leaders Should Be Asking

  • When were our transfer impact assessments last updated, and what material changes have occurred in the relevant transfer environments since those dates?
  • What treatment actions were recommended in our TIAs, and what proportion of those recommendations have been implemented with verified outcomes?
  • Do we have a process for detecting changes in third-country legal environments that trigger TIA reassessment obligations?
  • What is our process for reassessing cross-border transfer risk when a vendor changes their infrastructure geography or adds new subprocessors in new jurisdictions?
  • Who owns the ongoing management of cross-border data risk in our organization, and are they resourced to sustain active management rather than periodic documentation?

What to Require From Vendors

Ask directly:

"Have there been any material changes to the geographic location of your infrastructure or processing operations since our last transfer impact assessment, and what is your process for notifying customers of changes that affect the cross-border transfer risk profile of our relationship?"

Expect as evidence:
  • Current documentation of infrastructure geography with any changes since last customer assessment
  • A defined notification process for material changes to processing geography
  • Updated data processing documentation reflecting current subprocessor geography
  • Evidence supporting reassessment of any TIA-recommended supplementary measures

A vendor who cannot confirm whether their processing geography has changed since your last assessment has not maintained the transparency that ongoing cross-border transfer governance requires.

Demonstrating Diligence

  • Documentation: TIA currency tracking with reassessment history; risk treatment action records with implementation verification; regulatory environment monitoring records.
  • Process: Defined TIA reassessment triggers for environmental changes; vendor change notification review process; ongoing risk treatment tracking with accountability.
  • Technical evidence: TIA update records showing currency; supplementary measure implementation evidence; vendor processing geography current documentation.

Active risk management is demonstrated through the evidence of ongoing management activity: current assessments, implemented treatment actions, and monitoring records. Documentation from 2022 demonstrates active management in 2022.

Closing Perspective

Cross-border data risk management is not a compliance program that is completed and filed. It is an ongoing operational discipline applied to data flows that are continuous, in legal environments that change, with vendors that evolve, and under regulatory expectations that are increasing.

The organizations that invested in identification have valuable governance assets in their TIA archives. The organizations that invested in ongoing management are the ones that are getting the value from those assets by keeping them current, implementing their recommendations, and using them as active governance instruments rather than historical documents.

The gap between documented risk and managed risk is not a compliance gap in the traditional sense. It is an organizational discipline gap. Closing it requires treating cross-border data governance as an ongoing program rather than a completed project.

Cross-border risk that is identified and not managed is risk that the organization has decided to carry without deciding to carry it. Make the decision explicitly and manage accordingly.

Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.