| name | compliance-auditor-mittuled |
| title | compliance-auditor |
| description | This skill conducts comprehensive compliance audits across 7 regulatory frameworks using a 57-item checklist with quantitative scoring and remediation guidance. Use when preparing for certification audits (SOC 2, ISO 27001) or regulatory reviews. Also consider when onboarding enterprise customers with compliance requirements. Suggest when annual compliance review cycle begins. |
| author | mittuled |
| author_url | https://github.com/mittuled/skill-os/tree/main/agents/legal/security-compliance-programme-manager/compliance-auditor |
| license | MIT |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | regulatory |
| language | en |
compliance-auditor
Agent: Security & Compliance Programme Manager
L2 security and compliance programme manager (1x) responsible for SOC 2, security awareness training, disaster recovery, GDPR/CCPA compliance, and penetration test programme management.
Department ethos: ideal-legal.md
Tool policy: allowed-tools.yaml
Skill Description
Conducts comprehensive compliance audits across 7 regulatory frameworks using a 57-item checklist with quantitative scoring, gap identification, and prioritized remediation roadmaps.
When to Use
- When preparing for a certification audit (SOC 2 Type I/II, ISO 27001) or regulatory review and the company needs to understand its current compliance posture.
- When onboarding enterprise customers who require evidence of compliance with specific frameworks (HIPAA, PCI DSS, GDPR) as a procurement condition.
- When the annual compliance review cycle begins and cross-framework compliance status must be assessed and reported to leadership.
Workflow
-
Determine Applicable Frameworks: Assess which of the 7 supported frameworks apply based on business type, geography, customer requirements, and data handled. Adjust framework weights in the scoring rubric (see scoring-rubric.md) based on applicability — frameworks that do not apply receive zero weight and their weight is redistributed proportionally. Deliverable: framework applicability assessment with weight adjustments.
-
Select Checklist Items: From the 57-item master checklist (see checklist.md), select items relevant to the applicable frameworks. For each selected item, confirm the requirement text, evidence needed, and severity rating. Deliverable: tailored checklist with applicable items and evidence requirements.
-
Gather Evidence: For each checklist item, collect evidence: policies, procedures, technical control configurations, access logs, training records, audit trails, and vendor assessments. Record evidence source, collection date, and completeness. Deliverable: evidence inventory mapped to checklist items.
-
Score Each Item: Score each checklist item as Compliant (control documented, implemented, and tested), Partially Compliant (control exists but has gaps in documentation, implementation, or testing), or Non-Compliant (control absent or fundamentally deficient). Rate evidence quality for each item. Deliverable: scored checklist with status, evidence rating, and findings per item.
-
Calculate Framework Scores: Calculate the compliance score for each applicable framework using the scoring rubric criteria and weights. Compute the overall composite score across all frameworks. Deliverable: framework-level and composite compliance scores with grade.