California CPPA: regulations on risk assessments

A risk assessment before processing that presents significant risk, incl. using ADMT for significant decisions; attestations and summaries submitted to the Agency

From clause to evidenceThe chain from California CPPA CCPA regulations (risk assessments) to its evidence record, in 6 steps; the text alternative lists them and the facts under the figure state each in full.ClauseCalifornia CPPACCPAregulationsDuty holderBusinessessubject…Applies from2026-01-01In forceArtefactRisk assessmentper triggering…LayerLayer 05Assurance &ContinuousComplianceEvidence recordEvidence recordv1Same topic elsewhere: no crosswalk topic files this clause yetAs of 2026-09-24 · illustrative, not a claim of conformity From clause to evidenceThe chain from California CPPA CCPA regulations (risk assessments) to its evidence record, in 6 steps; the text alternative lists them and the facts under the figure state each in full.ClauseCalifornia CPPA · CCPA regulationsDuty holderBusinesses subject…Applies from2026-01-01 · In forceArtefactRisk assessment per triggering…LayerLayer 05Assurance & Continuous ComplianceEvidence recordEvidence record v1Same topic elsewhere: no crosswalk topicfiles this clause yetAs of 2026-09-24illustrative, not a claim of conformity
From clause to evidence Build the artefact, then file every output it produces as a record that names AIGE-OBL-USCA-CPPA-RA. Drawn from chapter 08.
Text alternative
  • Clause: California CPPA, CCPA regulations.
  • Duty holder: Businesses subject….
  • Applies from: 2026-01-01, In force.
  • Artefact: Risk assessment per triggering….
  • Layer: Layer 05 Assurance & Continuous Compliance.
  • Evidence record: Evidence record v1.
  • Record schema: Evidence record.
  • No crosswalk topic files this clause yet.
Id
AIGE-OBL-USCA-CPPA-RA
Instrument
California CPPA regulations (ADMT, risk assessments, cybersecurity audits) law
Clause
CCPA regulations (risk assessments)
In scope
Businesses subject to the CCPA
Authority
California Privacy Protection Agency
Applies from
In force · attestations and summaries due 2028-04-01
Later dates
  • Attestations and summaries due to the Agency

The artefact that evidences it

Risk assessment per triggering activity; submission record.

Patterns that build it

No pattern in the catalogue names this clause on its "Maps to" line yet; the artefact above is the engineering answer.

Source

Chapter 08, section State privacy and sector laws, checked against its sources on the review date above.

Machine-readable

Cite this obligation

García Aibar, J. (2026). California CPPA: regulations on risk assessments (AIGE-OBL-USCA-CPPA-RA). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-usca-cppa-ra. CC BY 4.0

BibTeX

@misc{aige2026obligation,
  author       = {Jorge García Aibar},
  title        = {{California CPPA: regulations on risk assessments (AIGE-OBL-USCA-CPPA-RA)}},
  howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
  year         = {2026},
  version      = {0.5.0},
  doi          = {10.5281/zenodo.22956197},
  url          = {https://aigovernanceengineer.com/obligations/aige-obl-usca-cppa-ra},
  note         = {Version 0.5.0}
}