Skip to main content

Checklist · 14 items

Youth Program Data Audit Checklist

Before you can fix scattered data, you have to see all of it. This checklist walks you through a complete inventory of everywhere participant information lives, then through the four risks that scattered data creates: duplicate people, untraceable report figures, consent gaps, and uncontrolled access. Plan a working session of about an hour with the people who actually run intake and reporting — not just leadership.

Inventory: find every place participant data lives

You cannot govern data you haven't located. Most organizations find more stores than they expected — that is the point of the exercise, not a failure.

  • List every active form

    Registration, application, waiver, and survey forms — online and paper. For each, note which account it lives in and who can log into that account. Forms created under a staff member's personal login are the ones that vanish when they do.

  • Inventory every spreadsheet holding participant names

    Search shared drives, then ask each program lead directly — the honest answer usually includes personal working copies. Expect roughly one workbook per program per year. Note last-modified dates; stale copies are a duplicate-data risk of their own.

  • Sweep shared drives for exports, scans, and old systems

    Rosters exported from other tools, scanned sign-in sheets, photos of paper forms, report drafts with names in them, and export files from any system you've retired. If it still holds participant records, it is in scope.

  • Check inboxes being used as filing systems

    If applications, consent forms, or referral details arrive by email, the inbox is a data store. Note whose inboxes, how far back the attachments go, and whether anything is ever moved somewhere governed.

  • Walk the physical spaces

    File cabinets, binders, and sign-in clipboards at every program site. Record what exists only on paper — that is the data you cannot search, back up, report from, or protect with a password.

Duplicate-person risk

Every separate store you just found is a place the same person can exist again. Measure the problem before deciding what to do about it.

  • Trace ten multi-program participants

    Pick ten people you know are active in more than one program. Count how many separate records each one has across all the sources above. If the answer is usually more than one, every unique-people figure you report is built on sand.

  • Compare identity fields across sources

    Same person, three spellings; birthdates in two formats; a guardian's phone number recorded as the participant's. Note which identity fields each source actually captures — your ability to match people later depends entirely on them.

  • Test whether you can see households

    Can you tell from your records that two participants are siblings, or that one family works with three of your programs? If household connections exist only in staff memory, write that down as a finding.

Reporting obligations

Now connect what you owe to where it comes from. This is where the audit starts paying for itself.

  • Map every required report to its sources

    List each report you owe — funders, board, council, network — and for every figure in it, the exact spreadsheet, form account, or binder it is compiled from. A figure with no traceable source is a finding, not a footnote.

  • Flag every manually de-duplicated number

    Anywhere someone eyeballs rosters to remove repeats before reporting, mark it. Those figures change depending on who compiles them and when — and they are the first thing an attentive program officer questions.

Consent

Consent gaps rarely announce themselves. They surface when a photo is published or a report is shared — which is the worst possible moment.

  • Match each collection point to a consent

    For every form and intake process, confirm that a signed consent or authorization exists, where it is stored, and whether it covers what you actually do with the data — photos, evaluation, sharing with partner organizations.

  • Check consent currency

    Note consents that are missing, expired, or written for a program the participant left two years ago. Flag any data whose current use isn't clearly covered before it feeds another report or photo wall.

Access control

Finish by asking who can touch each store. The answers here usually drive the most immediate fixes.

  • List who can open, edit, and export each store

    For every spreadsheet, drive folder, form account, and file cabinet: who can view it, who can change it, who can copy it out? “Everyone on staff” is an answer worth writing down verbatim.

  • Audit departed access

    Check whether former staff, interns, and volunteers still hold logins, shared links, or drive access. Personal email accounts that once received participant attachments count too — access doesn't expire on its own.

What to do with the results

Don't try to fix everything at once. Rank findings by exposure: uncontrolled access and consent gaps first, untraceable report figures second, duplicate records third. If the audit convinces you the real problem is structural — many stores, no shared record — that's what a connected participant and household record and role-based governance exist to solve.

See how BridgeCase makes these practices automatic.

One record per person, duplicate checks at intake, screening and consent tracking, and reports computed from source records — the practices in these guides, built into the system.

No youth or family data is required to request a demo.