PM-24: Data Integrity Board

PM-24 requires federal agencies to establish a Data Integrity Board that reviews every proposal to conduct or participate in a computer

Quick-reference card

FieldValue
Control IDPM-24
Control NameData Integrity Board
FrameworkNIST SP 800-53 Revision 5
Control FamilyProgram Management
BaselinesPRIVACY
RelevanceOrganization (First Party)
Risk SeverityLow

What this control requires

PM-24 requires federal agencies to establish a Data Integrity Board that reviews every proposal to conduct or participate in a computer matching program. The board must also perform an annual review of all matching programs the agency has participated in during the prior year.

A matching program, under the Privacy Act, is a computerized comparison of records drawn from two or more automated systems of records, or from a federal system and records maintained by a non-federal entity. These comparisons typically involve federal benefit programs or federal personnel and payroll records. The Data Integrity Board exists to ensure that each matching activity has a lawful basis, follows established agreements, and protects the personally identifiable information (PII) of individuals whose records are compared.

At a minimum, the board must include the agency’s Inspector General (if one exists) and the senior agency official for privacy. You can find the full NIST SP 800-53 framework index for additional context on how PM-24 fits within the broader set of program management controls.

Why it matters

Most agencies treat the Data Integrity Board as a paperwork formality, but its oversight function is the primary mechanism preventing unauthorized or poorly governed matching activities. Without active board review, matching programs can operate outside established agreements, expose PII unnecessarily, and create compliance gaps that surface during audits.

Failure to maintain this control introduces audit risk and may result in certification withdrawal or regulatory findings. Federal privacy audits specifically examine whether the board met its review obligations, whether matching agreements were current, and whether annual reviews were documented. A missing or inactive board is one of the fastest ways to trigger a finding in a privacy compliance assessment.

The consequences extend beyond audit outcomes. Agencies that skip annual reviews lose visibility into which matching programs are active, which agreements have expired, and which programs no longer have a valid operational justification. Over time, this governance gap compounds into a broader data stewardship problem.

In practice, the board’s annual review requirement creates a forcing function for accountability. It compels agencies to inventory every active matching program, verify that computer matching agreements remain valid, and confirm that participating entities are meeting their obligations under those agreements.

What attackers exploit:

  • Stale or expired computer matching agreements that lack current security requirements, creating data-sharing channels with outdated protections
  • Absence of board oversight, allowing unauthorized matching activities to process PII without appropriate review
  • Gaps in annual review documentation, which prevent agencies from detecting matching programs that have drifted outside their authorized scope
  • Weak coordination between the Data Integrity Board and the senior agency official for privacy, leaving matching proposals without adequate privacy impact analysis

How to implement

For your organization

The most common failure with PM-24 isn’t the absence of a board. It’s establishing one on paper and then never convening it. Effective implementation requires both structural setup and an operational cadence that the board follows consistently.

Step 1: Establish the board formally. Draft a charter that defines the board’s composition, authority, meeting frequency, quorum requirements, and decision-making process. At minimum, include the Inspector General and the senior agency official for privacy. Designate a chair and assign administrative support for scheduling reviews and maintaining records.

Step 2: Build a matching program inventory. Before the board can review anything, you need a complete list of all active and proposed matching programs. Work with program offices, privacy staff, and data-sharing partners to identify every computerized comparison of records that qualifies as a matching program under the Privacy Act.

Step 3: Create a proposal review workflow. Define how new matching program proposals reach the board. Each proposal should include the legal authority for the match, a description of the records involved, the purpose of the comparison, data retention and disposal plans, and a privacy impact assessment. The board reviews, approves, or rejects each proposal before any matching activity begins.

Step 4: Conduct and document annual reviews. Schedule the annual review at the same time each year. For each active matching program, the board should verify that the computer matching agreement is current, that the program is operating within its authorized scope, and that participating entities are meeting their obligations. Document the review findings, any corrective actions required, and the board’s determination for each program.

Step 5: Maintain records for audit readiness. Store the board’s charter, meeting minutes, proposal review decisions, annual review reports, and all associated matching agreements in a centralized repository. These records form the primary evidence base for privacy audits and FedRAMP assessments.

Common mistakes include treating the annual review as a checkbox exercise without examining whether matching programs are still justified, failing to update computer matching agreements when program parameters change, and not documenting board decisions with enough specificity to satisfy auditors.

Evidence examples

Evidence TypeExample Artifact
Board establishment documentationData Integrity Board charter defining composition, authority, quorum rules, and decision-making procedures
Privacy program planAgency-wide privacy program plan identifying the Data Integrity Board’s role and its relationship to privacy governance
Computer matching agreementsSigned agreements for each matching program specifying records compared, legal authority, retention schedules, and security requirements
Proposal review recordsBoard meeting minutes documenting review and approval or rejection of each proposed matching program
Annual review reportsDocumented findings from the board’s annual review of all active matching programs, including compliance determinations
Information sharing agreements and memoranda of understandingAgreements with non-federal entities participating in matching programs, specifying data handling and security obligations
Governing requirements referenceCompiled index of applicable laws, executive orders, regulations, and guidance governing the agency’s matching program activities

Cross-framework mapping

No applicable cross-framework mappings for this control.

PM-24’s scope is specific to federal matching program governance under the Privacy Act, which means frameworks like NIST SP 800-171 don’t include an equivalent control. SP 800-171 focuses on protecting controlled unclassified information in non-federal systems and doesn’t address the institutional oversight structures required for computerized record matching.

The following controls within the Program Management family and other families support or depend on PM-24’s governance function. You can also explore related access control requirements on the AC-1 Policy and Procedures page for additional context on how policy controls intersect with program management.

  • AC-04 — Information Flow Enforcement: Enforces approved information flow paths, which is directly relevant when matching programs transfer records between systems or agencies.
  • PM-19 — Privacy Program Leadership Role: Designates the senior agency official for privacy, who serves as a required member of the Data Integrity Board.
  • PM-23 — Data Governance Body: Establishes the broader data governance structure within which the Data Integrity Board operates as a specialized oversight function.
  • PT-02 — Authority to Process Personally Identifiable Information: Defines the legal authorities under which PII can be processed, providing the authorization basis that the Data Integrity Board evaluates for each matching program.
  • PT-08 — Computer Matching Requirements: Specifies the detailed requirements for computer matching agreements that the Data Integrity Board reviews and approves.

Frequently asked questions

What is NIST SP 800-53 PM-24?

PM-24 is the NIST SP 800-53 control that requires federal agencies to establish a Data Integrity Board responsible for reviewing proposals to conduct or participate in matching programs. The board must include, at minimum, the agency’s Inspector General and the senior agency official for privacy. It also conducts an annual review of all matching programs in which the agency has participated, verifying that computer matching agreements remain current and that each program operates within its authorized scope.

What happens if PM-24 is not implemented?

Without an active Data Integrity Board, an agency has no formal governance mechanism for reviewing matching program proposals or verifying ongoing compliance with computer matching agreements. Auditors will flag the absence of annual review documentation as a privacy control deficiency. The resulting finding can affect the agency’s overall privacy posture rating and, in some cases, delay or jeopardize authorization decisions for systems that depend on matching program data.

How do you audit PM-24?

Auditing PM-24 starts with verifying that the Data Integrity Board has been formally established through a documented charter and that its membership meets the minimum requirements. Auditors then examine records of proposal reviews to confirm the board evaluated each matching program before it became operational. The annual review is a critical audit artifact, so auditors look for documented findings covering every active matching program, including the board’s determination on whether each program should continue, be modified, or be terminated.

What is a matching program under the Privacy Act?

A matching program is a computerized comparison of records from two or more automated Privacy Act systems of records, or between a federal system and automated records maintained by a non-federal entity. These comparisons relate to federal benefit programs or federal personnel and payroll records. The Privacy Act requires agencies to establish specific governance structures, including the Data Integrity Board, to oversee these activities and ensure that individuals’ PII is protected throughout the matching process.

Experience superior visibility and a simpler approach to cyber risk management