PT-6: System of Records Notice

PT-06 requires federal agencies to draft, submit, publish, and maintain system of records notices (SORNs) whenever they operate a system

Quick-reference card

FieldValue
Control IDPT-06
Control NameSystem of Records Notice
FrameworkNIST SP 800-53 Revision 5
Control FamilyPersonally Identifiable Information Processing and Transparency
BaselinesPRIVACY
RelevanceOrganization (First Party)
Risk SeverityLow

What this control requires

PT-06 requires federal agencies to draft, submit, publish, and maintain system of records notices (SORNs) whenever they operate a system that retrieves personal information by an individual’s name or unique identifier. The control exists because without a public, accurate notice, individuals have no way to know that an agency collects and uses their data, and oversight bodies have no mechanism to review whether that use is lawful.

In practice, this means your organization must prepare each SORN in line with OMB guidance, route new or substantially revised notices through OMB and the appropriate congressional committees for advance review, and then publish the final notice in the Federal Register. The PT control family groups this requirement alongside related transparency and processing controls because public notice is a foundational safeguard under the Privacy Act.

The obligation doesn’t end at publication. You must keep every active SORN accurate, current, and properly scoped so it reflects the actual records your systems hold, the categories of individuals covered, and the routine uses to which those records are subject. Letting a SORN go stale is functionally the same as not having one at all.

Why it matters

Most compliance gaps tied to SORNs aren’t dramatic data breaches. They’re documentation failures that surface during audits, congressional inquiries, or Inspector General reviews and result in formal findings, corrective action plans, and reputational harm with oversight bodies. For agencies subject to the NIST SP 800-53 framework, a missing or outdated SORN signals a systemic weakness in privacy governance.

The risk compounds over time. When an agency launches a new system or modifies an existing one without updating its SORN, the gap between what’s published in the Federal Register and what’s actually happening widens. Auditors reviewing Privacy Act compliance treat that divergence as evidence that the agency’s privacy program lacks operational discipline.

Noncompliance also creates legal exposure. The Privacy Act provides individuals with a cause of action when agencies fail to maintain required records accurately or disclose records without proper authority. An inaccurate or missing SORN undermines the agency’s defense in those proceedings because it removes the documented basis for how records are used.

Beyond audit and legal risk, outdated SORNs erode trust with the public and with Congress. When oversight committees discover that an agency collects sensitive data without proper notice, it can trigger hearings, budget scrutiny, and mandatory remediation timelines.

What auditors and oversight bodies look for

  • SORNs that don’t reflect current system boundaries, leaving entire categories of records undisclosed
  • Failure to submit new or significantly modified notices to OMB and congressional committees before publication
  • Published notices that omit required fields such as routine uses, categories of individuals, or authority for maintenance
  • Systems retrieving records by personal identifiers that lack a corresponding published SORN entirely
  • No documented review cadence to keep existing SORNs aligned with operational changes

How to implement

The most common failure mode with PT-06 isn’t ignorance of the requirement. It’s the lag between system changes and SORN updates. Agencies typically know they need notices, but the drafting-review-publication pipeline moves slowly while system modifications happen continuously.

For your organization

1. Inventory your Privacy Act systems of records. Start by identifying every system under agency control that retrieves information by an individual’s name or other personal identifier. Map each system to its existing SORN or flag it as uncovered. This inventory becomes your baseline.

2. Establish a SORN drafting workflow. Build a repeatable process for drafting notices that follows OMB Circular A-108 requirements. Each notice must cover the system’s name and location, the categories of individuals and records, the purpose and authority for maintaining the system, routine uses, and policies for retention, retrieval, and safeguards. Assign clear ownership for drafting, legal review, and approval.

3. Route notices through advance review. Before publishing, submit new and significantly modified SORNs to OMB and the relevant congressional committees. Build this step into your workflow with defined timelines so the review doesn’t bottleneck publication. Document the submission dates and any feedback received.

4. Publish in the Federal Register. Work with your agency’s Federal Register liaison to submit the final notice for publication. Retain proof of publication, including the Federal Register citation and date, as part of your compliance evidence.

5. Implement a periodic review cycle. Establish a defined cadence, at minimum annually, for reviewing every active SORN against current system configurations. Compare the published notice against the actual records maintained, the categories of individuals covered, and the routine uses in effect. A compliance monitoring process tied to system change management helps catch drift before an audit does.

6. Integrate SORN reviews with system lifecycle events. Any time a system undergoes a significant modification, retirement, or new deployment, trigger a SORN review as part of the change management process. This prevents the documentation lag that produces most PT-06 findings.

Common mistakes to avoid:

  • Treating SORN maintenance as a one-time activity rather than an ongoing obligation
  • Failing to update notices when routine uses change, even if the system itself remains the same
  • Publishing notices that use boilerplate language without reflecting the specific records and purposes of each system
  • Skipping the congressional committee submission step for modifications that appear minor but meet the “significant” threshold

For a broader view of how PT-06 fits into your overall framework compliance program, the NIST 800-53 compliance checklist covers implementation sequencing across control families.

Evidence examples

Evidence TypeExample Artifact
Privacy governance policyPII processing and transparency policy defining SORN drafting responsibilities, review cadence, and publication workflows
System of records inventoryRegister of all Privacy Act systems of records with SORN status, Federal Register citation, and last review date
Federal Register publicationsPublished SORN notices with Federal Register volume, page number, and publication date for each covered system
OMB and congressional submissionsAdvance review submission records including dates, recipient committees, and any OMB feedback or conditions
SORN review documentationPeriodic review records showing comparison of published SORN content against current system configuration and routine uses
Privacy planAgency privacy plan referencing SORN maintenance procedures, responsible officials, and integration with system lifecycle processes

Cross-framework mapping

No cross-framework mappings have been configured for this control.

  • AC-03 — Access Enforcement: Access controls implement the boundaries that SORNs publicly describe, ensuring records are only accessed in accordance with documented routine uses and authorities.
  • PM-20 — Dissemination of Privacy Program Information: While PT-06 focuses on Federal Register notices for specific systems, PM-20 addresses broader public communication about the agency’s overall privacy program and practices.
  • PT-02 — Authority to Process Personally Identifiable Information: PT-02 establishes the legal authority to process PII, and the SORN must cite that authority as a required field in every published notice.
  • PT-03 — Personally Identifiable Information Processing Purposes: The purposes documented under PT-03 feed directly into the SORN’s description of why the system maintains records and the routine uses it supports.
  • PT-05 — Privacy Notice: PT-05 covers direct notice to individuals at the point of collection, while PT-06 addresses the public notice published in the Federal Register describing the system’s existence and character.

Frequently asked questions

What is NIST SP 800-53 PT-06?

PT-06 is the NIST SP 800-53 control that requires federal agencies to draft, publish, and maintain system of records notices in the Federal Register for every system that retrieves personally identifiable information by name or unique identifier. The control covers the full lifecycle of a SORN, from initial drafting under OMB guidance through advance review by OMB and congressional committees to ongoing accuracy maintenance. Agencies must keep each notice scoped to reflect the actual categories of records maintained, routine uses, and authority for the system’s operation.

What happens if PT-06 is not implemented?

Failure to implement PT-06 creates a Privacy Act compliance violation that auditors and Inspectors General flag as a formal finding requiring corrective action. Without published Federal Register notices, individuals lose their statutory right to know that an agency maintains records about them and how those records are used. The gap also removes the documented basis for routine uses, which exposes the agency to legal challenges if records are disclosed without proper authority. Over time, missing or outdated SORNs signal systemic weakness in an agency’s privacy program and can trigger congressional oversight actions.

How do you audit PT-06?

Auditing PT-06 starts with comparing the agency’s inventory of Privacy Act systems of records against published Federal Register notices to confirm every covered system has a current, corresponding SORN. Examiners verify that each notice was submitted to OMB and appropriate congressional committees for advance review before publication, with documented submission dates and feedback. The audit also checks whether published notices include all required fields from OMB Circular A-108, such as categories of individuals, routine uses, and retention policies. Finally, auditors look for evidence of a periodic review process that keeps SORNs aligned with system changes over time, following NIST compliance assessment methodologies.

What is the difference between a privacy notice and a system of records notice?

A privacy notice under PT-05 is a direct notification provided to individuals at or before the point of collection, explaining what information is being gathered, why, and how it will be used. A system of records notice under PT-06 is a public document published in the Federal Register that describes an entire system’s existence, the categories of records it holds, and the routine uses to which those records are subject. Privacy notices are individual-facing and transaction-specific, while SORNs are system-level disclosures aimed at the public, OMB, and congressional oversight. Both are required, but they serve different transparency functions within the Personally Identifiable Information Processing and Transparency control family.

Experience superior visibility and a simpler approach to cyber risk management