PM-22: Personally Identifiable Information Quality Management

PM-22 requires organizations to establish policies and procedures that maintain the accuracy, relevance, timeliness, and completeness of

Quick-reference card

FieldValue
Control IDPM-22
Control NamePersonally Identifiable Information Quality Management
FrameworkNIST SP 800-53 Revision 5
Control FamilyProgram Management
BaselinesPRIVACY
RelevanceOrganization (First Party)
Risk SeverityMedium

What this control requires

PM-22 requires organizations to establish policies and procedures that maintain the accuracy, relevance, timeliness, and completeness of personally identifiable information (PII) throughout its entire life cycle. That life cycle spans creation, collection, use, processing, storage, maintenance, dissemination, disclosure, and disposition. Every stage introduces opportunities for PII to degrade in quality, and PM-22 exists to prevent that degradation from reaching a point where it harms individuals or compromises organizational decision-making.

In practice, this means your organization needs documented processes for four distinct activities. You must review PII for accuracy and relevance on a recurring basis. You must correct or delete records that are inaccurate or outdated. You must notify affected individuals and other appropriate entities when corrections or deletions occur. And you must provide a defined appeals process for individuals who receive adverse decisions on their correction or deletion requests.

The control sits within NIST SP 800-53’s Program Management family because PII quality isn’t a technical configuration you set once. It’s an organizational capability that requires governance, accountability, and continuous oversight from the senior agency official for privacy. Without that governance layer, data quality efforts become ad hoc and inconsistent, creating gaps that auditors will flag and that individuals will feel through denied benefits, incorrect records, or reputational harm.

Why it matters

Poor PII quality creates a compounding liability that most organizations underestimate until an audit or individual complaint exposes the gap. Inaccurate or outdated PII doesn’t just sit harmlessly in a database. It drives decisions, and when those decisions rely on flawed data, the consequences land on real people. Individuals can face denied benefits, incorrect eligibility determinations, or stigmatization based on records that no one reviewed or corrected.

The compliance risk is direct and measurable. Federal agencies subject to the Privacy Act face legal obligations to maintain accurate records, and privacy assessors evaluate PM-22 by checking whether documented policies exist, whether those policies address every phase of the information life cycle, and whether the organization can produce evidence of ongoing quality reviews. Failing to demonstrate these capabilities during an audit doesn’t require a data breach to create consequences. It signals a systemic governance failure that auditors escalate.

Beyond audit findings, weak PII quality management erodes trust with the individuals whose data you hold. When someone requests a correction and encounters an undefined process, or when corrected data isn’t propagated to downstream systems, the organizational credibility gap widens. That gap is harder to close than any technical vulnerability.

Data flows between systems and entities add another layer of complexity. When PII is shared across departments, partner agencies, or third-party processors, a correction in one system may not propagate to others without deliberate notification procedures. This is why PM-22 requires organizations to disseminate notices of corrected or deleted PII, not just make the fix internally.

What auditors and oversight bodies look for:

  • Absence of documented PII quality management policies covering the full information life cycle
  • No defined process for individuals to request corrections or deletions of their PII
  • Missing or inconsistent notification procedures when PII is corrected or deleted
  • No appeals mechanism for adverse decisions on correction or deletion requests
  • Inability to produce records showing that PII quality reviews actually occur on a recurring basis

Organizations that lack a structured risk assessment process for their data handling practices often discover PM-22 gaps only when an external review forces the issue. Integrating PII quality checks into your broader supply chain risk management and data governance programs prevents that reactive posture.

How to implement

For your organization

The most common failure with PM-22 implementation isn’t a missing policy document. It’s a policy that exists on paper but lacks the operational workflows to make it function. Start by ensuring your implementation connects written policy to repeatable processes with assigned owners.

Step 1: Develop PII quality management policies and procedures. Draft policies that explicitly address all four PM-22 requirements: accuracy review, correction and deletion, notification dissemination, and appeals handling. These policies should define review frequency, responsible roles, and escalation paths. Tie them to your broader privacy program plan rather than creating standalone documents that drift out of alignment.

Step 2: Map your PII inventory across the information life cycle. You can’t manage the quality of data you haven’t cataloged. Document where PII is created, collected, stored, processed, shared, and disposed of. Identify the systems and data flows involved at each stage. This mapping becomes the foundation for targeted quality reviews.

Step 3: Establish recurring quality review processes. Define how and when PII accuracy reviews occur. Automated data validation rules can catch formatting errors and outdated records, but manual review is often necessary for relevance and completeness assessments. Assign review cadences based on the sensitivity and volume of PII in each system.

Step 4: Build correction, deletion, and notification workflows. Create intake channels for individual correction and deletion requests. Define service-level expectations for processing those requests. Critically, build notification procedures that inform both the affected individual and any downstream entities that received the original data. Data flow complexity means a correction in your primary system may not reach partner systems without deliberate propagation.

Step 5: Implement an appeals process. Document how individuals can appeal adverse decisions on their correction or deletion requests. The process must be publicly available and clearly communicated. Many organizations overlook this requirement, which creates both a compliance gap and a trust deficit with data subjects.

Step 6: Monitor and produce evidence. Maintain records of quality reviews conducted, corrections and deletions processed, notifications sent, and appeals resolved. These records serve as the primary evidence artifacts during an assessment. Privacy management platforms and governance, risk, and compliance (GRC) tools can centralize this tracking, but even spreadsheet-based tracking satisfies the requirement if it’s consistent and auditable.

A common mistake is treating PM-22 as a one-time policy exercise. The control requires ongoing monitoring, which means building quality management into your operational rhythm rather than treating it as a document you file and forget. Aligning your PII quality practices with frameworks like the HIPAA Privacy Rule strengthens consistency across compliance programs. Integrating these practices into your broader information security management system reduces duplicated effort and keeps privacy controls aligned with your security posture.

Evidence examples

Evidence TypeExample Artifact
Privacy program planPrivacy program plan documenting PII quality management governance structure, roles, responsibilities, and integration with organizational risk management
PII quality management policyPolicy defining review procedures for accuracy, relevance, timeliness, and completeness of PII across all information life cycle stages
Correction and deletion proceduresDocumented workflows for processing PII correction and deletion requests, including intake channels, processing timelines, and responsible parties
Notification recordsSample notices sent to individuals and downstream entities when PII is corrected or deleted, including distribution logs
Appeals process documentationPublicly available procedures for appealing adverse decisions on PII correction or deletion requests, including escalation paths and resolution timelines
Quality review recordsLogs and reports from recurring PII accuracy and relevance reviews, showing review dates, findings, and remediation actions taken
Information life cycle documentationData inventory and flow maps documenting where PII is created, collected, processed, stored, shared, and disposed of across organizational systems

Cross-framework mapping

No applicable content for this control.

  • PM-23 — Data Governance Body: Establishes the governance structure that oversees PII quality management policies and ensures organizational accountability for data handling practices.
  • SI-18 — Personally Identifiable Information Quality Operations: Provides the operational and technical mechanisms that execute the quality management policies defined under PM-22 at the system level.

Frequently asked questions

What is NIST SP 800-53 PM-22

PM-22 is the NIST SP 800-53 control that requires organizations to develop and maintain policies for managing the quality of personally identifiable information throughout its entire information life cycle. These policies must address four areas: reviewing PII for accuracy and relevance, correcting or deleting inaccurate records, notifying individuals and entities of corrections or deletions, and handling appeals of adverse decisions. The control falls within the Program Management family and applies to organizations handling PII under the PRIVACY baseline.

What happens if PM-22 is not implemented

Without PM-22 implementation, organizations lack the governance structure to catch and correct inaccurate or outdated PII before it causes harm. Individuals may face denied benefits, incorrect eligibility determinations, or stigmatization based on flawed records that no one reviewed. Privacy assessors will flag the absence of documented PII quality management policies, information life cycle documentation, and correction or deletion notice procedures as material audit findings. These findings indicate systemic governance failures that can trigger regulatory scrutiny and erode stakeholder trust.

How do you audit PM-22

Auditing PM-22 starts with verifying that the organization has developed and documented PII quality management policies covering accuracy, relevance, timeliness, and completeness across the information life cycle. Assessors then examine whether those policies include defined processes for correcting or deleting inaccurate PII, disseminating correction or deletion notices to affected parties, and handling appeals of adverse decisions. The audit also requires evidence that these processes are operational, which means reviewing quality review records, sample correction and deletion notices, and privacy program plan documentation that shows ongoing monitoring rather than a one-time policy creation.

How does PM-22 differ from SI-18

PM-22 establishes the organizational policies and governance framework for PII quality management, while SI-18 operates at the system level to implement those policies through technical and operational controls. PM-22 defines what your organization must do, including review cadences, notification requirements, and appeals processes. SI-18 defines how individual systems execute those requirements through data validation checks, automated quality controls, and system-specific correction workflows. Organizations need both controls working together because policy without operational execution leaves PII quality gaps that auditors will identify.

Experience superior visibility and a simpler approach to cyber risk management