OneTrust Assessment Management API

The Assessment Management APIs are used to modify, link, and manage existing assessments.

Operations 7

PUT /api/assessment/v2/assessments/archive Archive Assessment #
POST /api/assessment/v2/assessments/assessment-links Link Assessments #
PUT /api/assessment/v2/assessments/un-archive Unarchive Assessment #
PATCH /api/assessment/v2/assessments/{assessmentId}/metadata Modify Assessment #
PUT /api/assessment/v2/assessments/{assessmentId}/primary-records Set Primary Record #
PUT /api/assessment/v2/assessments/{assessmentId}/soft-delete Move Assessment to Recycle Bin #
PUT /api/assessment/v2/assessments/{assessmentId}/tags Update Assessment Tags #

Documentation

📖
Documentation
https://developer.onetrust.com/onetrust/reference/attribute-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/activity-log
📖
Documentation
https://developer.onetrust.com/onetrust/reference/preferences-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/banner
📖
Documentation
https://developer.onetrust.com/onetrust/reference/consent-receipts
📖
Documentation
https://developer.onetrust.com/onetrust/reference/applications
📖
Documentation
https://developer.onetrust.com/onetrust/reference/categorizations
📖
Documentation
https://developer.onetrust.com/onetrust/reference/domain-data
📖
Documentation
https://developer.onetrust.com/onetrust/reference/preferences
📖
Documentation
https://developer.onetrust.com/onetrust/reference/mobile-app-data
📖
Documentation
https://developer.onetrust.com/onetrust/reference/privacy-notice-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/collection-points
📖
Documentation
https://developer.onetrust.com/onetrust/reference/catalog-search-v1
📖
Documentation
https://developer.onetrust.com/onetrust/reference/classification
📖
Documentation
https://developer.onetrust.com/onetrust/reference/custom-scan
📖
Documentation
https://developer.onetrust.com/onetrust/reference/carbon-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/audit-records
📖
Documentation
https://developer.onetrust.com/onetrust/reference/bulk-export
📖
Documentation
https://developer.onetrust.com/onetrust/reference/attachments
📖
Documentation
https://developer.onetrust.com/onetrust/reference/system-credentials
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory-relationships-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/model-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/tasks
📖
Documentation
https://developer.onetrust.com/onetrust/reference/groups-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/assessment-actions
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory-1
📖
Documentation
https://developer.onetrust.com/onetrust/reference/drop-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/incidents
📖
Documentation
https://developer.onetrust.com/onetrust/reference/document-controller
📖
Documentation
https://developer.onetrust.com/onetrust/reference/audits
📖
Documentation
https://developer.onetrust.com/onetrust/reference/initiatives
📖
Documentation
https://developer.onetrust.com/onetrust/reference/document-attachments
📖
Documentation
https://developer.onetrust.com/onetrust/reference/issues
📖
Documentation
https://developer.onetrust.com/onetrust/reference/control-implementations
📖
Documentation
https://developer.onetrust.com/onetrust/reference/training
📖
Documentation
https://developer.onetrust.com/onetrust/reference/contracts

Specifications

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/onetrust-assessment-management-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

onetrust-assessment-management-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Privacy Automation - Assessment Automation Assessment…
  version: '1.0'
  contact:
    name: OneTrust Support
    url: https://my.onetrust.com/s/contactsupport
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  description: The Assessment Automation APIs provide functionality for managing assessment template lifecycle operations, including template export and import for cross-environment migration, retrieving published template metadata with filtering by template type, and template deletion with comprehensive validation checks.
servers:
- url: https://{hostname}
  variables:
    hostname:
      default: hostname
      description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com.
tags:
- name: Assessment Management
  description: The Assessment Management APIs are used to modify, link, and manage existing assessments.
  externalDocs:
    description: OpenAPI 3.1.0 - Download Definition
    url: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json
  x-displayName: Assessment Management
paths:
  /api/assessment/v2/assessments/archive:
    put:
      operationId: archiveAssessmentsUsingPUT
      summary: Archive Assessment
      description: 'Use this API to archive a single assessment or multiple assessments. Multiple assessment IDs can be provided in the API request to archive assessments in bulk.


        > 🗒 Things to Know

        >

        > - Archived assessments will be moved into the Archive list after archiving.

        >

        > - Archived assessments will be read-only.

        >

        > - Dynamic Incident Notification Assessments, Program Benchmarking Assessments, and Maturity & Planning Assessments cannot be archived.'
      tags:
      - Assessment Management
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: array
              items:
                type: string
                format: uuid
            examples:
              Assessment IDs:
                description: Assessment IDs
                value:
                - 550e8400-e29b-41d4-a716-446655440000
                - 550e8400-e29b-41d4-a716-446655440001
      responses:
        '204':
          description: No Content
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - PrivacyAutomation-AssessmentAutomation_OAUTH2:
        - ASSESSMENT
  /api/assessment/v2/assessments/assessment-links:
    post:
      operationId: addManualAssessmentLinksUsingPOST
      summary: Link Assessments
      description: 'Use this API to link an assessment to multiple assessments.


        > 🗒 Things to Know

        >

        > - This API can be used for linking active and archived assessments.

        >

        > - Only assessments with the following template types can be linked: PIA, Vendor, ITRM, Control, Exchange, Incident and ESG.'
      tags:
      - Assessment Management
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PrivacyAutomation-AssessmentAutomation_AssessmentManualLinkRequest'
      responses:
        '201':
          description: Created
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - PrivacyAutomation-AssessmentAutomation_OAUTH2:
        - ASSESSMENT
  /api/assessment/v2/assessments/un-archive:
    put:
      operationId: unarchiveAssessmentsUsingPUT
      summary: Unarchive Assessment
      description: 'Use this API to unarchive a single assessment or multiple assessments. Multiple assessment IDs can be provided in the API request to unarchive assessments in bulk.


        > 🗒 Things to Know

        >

        > - Unarchived assessments will be moved back to the Active list after unarchiving.

        >

        > - Unarchived assessments will be editable.

        >

        > - Dynamic Incident Notification Assessments, Program Benchmarking Assessments, and Maturity & Planning Assessments cannot be unarchived.'
      tags:
      - Assessment Management
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: array
              items:
                type: string
                format: uuid
            examples:
              Single Assessment:
                summary: Unarchive a single assessment
                description: Single Assessment
                value:
                - 550e8400-e29b-41d4-a716-446655440000
              Multiple Assessments:
                summary: Unarchive multiple assessments in bulk
                description: Multiple Assessments
                value:
                - 550e8400-e29b-41d4-a716-446655440000
                - 550e8400-e29b-41d4-a716-446655440001
                - 550e8400-e29b-41d4-a716-446655440002
      responses:
        '204':
          description: No Content
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - PrivacyAutomation-AssessmentAutomation_OAUTH2:
        - ASSESSMENT
  /api/assessment/v2/assessments/{assessmentId}/metadata:
    patch:
      operationId: updateBasicAssessmentDetailsUsingPATCH
      summary: Modify Assessment
      description: 'Use this API to update basic assessment details such as assessment name, assessment description, assessment deadline and reminder.


        > 🗒 Things to Know

        >

        > - If the assessment is in **Completed** stage, updates made using this API will be ignored.

        >

        > - If an update is made using this API, an event will be shown in the Assessment Activity.

        >

        > - This API can update assessments of the following types: PIA, Vendor, ITRM, Control, Exchange and Incident.'
      tags:
      - Assessment Management
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json
      parameters:
      - name: assessmentId
        in: path
        description: UUID of the assessment to update
        required: true
        schema:
          type: string
          format: uuid
        example: 550e8400-e29b-41d4-a716-446655440000
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PrivacyAutomation-AssessmentAutomation_AssessmentBasicDetailsUpdateRequest'
      responses:
        '204':
          description: No Content
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - PrivacyAutomation-AssessmentAutomation_OAUTH2:
        - ASSESSMENT
  /api/assessment/v2/assessments/{assessmentId}/primary-records:
    put:
      operationId: updatePrimaryRecordUsingPUT
      summary: Set Primary Record
      description: 'Use this API to edit the existing primary record or set a new primary record on an assessment. For the given `assessmentId`, the existing primary record will either be updated or a new primary record will be created using the attributes in the API request body.


        > 🗒 Things to Know

        >

        > - If the template has a question with the primary record enabled, then the primary record is set as the response to that question and the related attributes and inventory questions will be pre-populated.

        >

        > - The primary record can be edited for Inventory and Assess Control primary record types.

        >

        > - The primary record list cannot be greater than 1 for Inventory primary record types.

        >

        > - The primary record list can be greater than 1 for Assess Control primary record types.'
      tags:
      - Assessment Management
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json
      parameters:
      - name: assessmentId
        in: path
        description: UUID of the assessment to update primary record for
        required: true
        schema:
          type: string
          format: uuid
        example: 550e8400-e29b-41d4-a716-446655440000
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PrivacyAutomation-AssessmentAutomation_AssessmentPrimaryRecordUpdateRequest'
      responses:
        '204':
          description: No Content
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - PrivacyAutomation-AssessmentAutomation_OAUTH2:
        - ASSESSMENT
  /api/assessment/v2/assessments/{assessmentId}/soft-delete:
    put:
      operationId: softDeleteAssessmentUsingPUT
      summary: Move Assessment to Recycle Bin
      description: 'Use this API to soft delete an assessment by moving it to the recycle bin. The assessment will then be stored in the recycle bin until it is either restored or permanently deleted.


        > 🗒 Things to Know

        >

        > - Only assessments found in the PIA & DPIA Automation and IT & Security Risk Management modules can be soft deleted.

        >

        > - Dynamic Incident Notification Assessments, Program Benchmarking Assessments, and Maturity & Planning Assessments cannot be soft deleted.'
      tags:
      - Assessment Management
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json
      parameters:
      - name: assessmentId
        in: path
        description: UUID of the assessment to soft delete
        required: true
        schema:
          type: string
          format: uuid
        example: 550e8400-e29b-41d4-a716-446655440000
      responses:
        '204':
          description: No Content
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - PrivacyAutomation-AssessmentAutomation_OAUTH2:
        - ASSESSMENT
  /api/assessment/v2/assessments/{assessmentId}/tags:
    put:
      operationId: addOrUpdateTagsUsingPUT
      summary: Update Assessment Tags
      description: 'Use this API to update the tags associated with a specific assessment. The tags submitted through this API will overwrite all existing tags on the assessment.


        > 🗒 Things to Know

        >

        > - The Get Assessment API can be used to retrieve the current list of assessment tags for the specified assessment. You can include these tags within the request of this API to keep them on the assessment.

        >

        > - New tags can be created using this API and can then be associated with an assessment.'
      tags:
      - Assessment Management
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json
      parameters:
      - name: assessmentId
        in: path
        description: UUID of the assessment to update tags for
        required: true
        schema:
          type: string
          format: uuid
        example: 550e8400-e29b-41d4-a716-446655440000
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: array
              items:
                type: string
            examples:
              Tags:
                description: Tags
                value:
                - GDPR
                - SIG
                - tag3
      responses:
        '204':
          description: No Content
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - PrivacyAutomation-AssessmentAutomation_OAUTH2:
        - ASSESSMENT
components:
  schemas:
    PrivacyAutomation-AssessmentAutomation_AssessmentBasicDetailsUpdateRequest:
      type: object
      properties:
        name:
          description: The name of the assessment to be displayed in the UI
          type: string
          example: GDPR Compliance Assessment 2025
          maxLength: 255
        description:
          description: Detailed description of the assessment's purpose and scope
          type: string
          example: This assessment evaluates the organization's compliance with GDPR requirements and identifies potential data protection gaps
          maxLength: 4000
        deadline:
          description: The date by which the assessment must be completed
          type: string
          format: date-time
          example: '2025-12-31T23:59:59.000Z'
        reminder:
          description: The number of days before the deadline when a reminder notification should be sent to respondents
          type: integer
          format: int32
          example: 7
          minimum: 1
    PrivacyAutomation-AssessmentAutomation_AssessmentPrimaryRecordUpdateRequest:
      type: object
      properties:
        primaryRecordType:
          description: Type of Inventory record to be updated.
          type: string
          example: ASSETS
          enum:
          - ASSETS
          - PROCESSING_ACTIVITY
          - VENDORS
          - ENTITIES
          - ASSESS_CONTROL
          - ENGAGEMENT
        primaryRecordIds:
          description: The unique UUIDs of the primary records
          type: array
          items:
            type: string
            format: uuid
          example:
          - 550e8400-e29b-41d4-a716-446655440000
          - 550e8400-e29b-41d4-a716-446655440001
          minimum: 1
          minItems: 1
          uniqueItems: true
      required:
      - primaryRecordIds
      - primaryRecordType
    PrivacyAutomation-AssessmentAutomation_AssessmentManualLinkRequest:
      type: object
      properties:
        fromId:
          description: The unique ID of the source assessment to create the link from
          type: string
          format: uuid
          example: 123e4567-e89b-12d3-a456-426614174000
        toIds:
          type: array
          items:
            type: string
            format: uuid
            example: 223e4567-e89b-12d3-a456-426614174001
          maxItems: 2147483647
          minItems: 1
          uniqueItems: true
      required:
      - fromId
      - toIds
  securitySchemes:
    PrivacyAutomation-AssessmentAutomation_OAUTH2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://{hostname}/api/access/v1/oauth/token
          scopes:
            ASSESSMENT: Access to assessment scope for external systems
            ASSESSMENT_READ: Access to read assessment scope for external systems
    Template_OAUTH2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://{hostname}/api/access/v1/oauth/token
          scopes:
            ASSESSMENT: Access to assessment scope for external systems
            ASSESSMENT_READ: Access to read assessment scope for external systems
x-readme:
  explorer-enabled: false
  proxy-enabled: false
  metrics-enabled: false
x-onetrust:
  spec-label: OpenAPI 3.1.0