audit-prep

Assess ISO 27001:2022 audit readiness and generate a Markdown Readiness Report.

Updated Apr 28, 2026
One-click install
npx skills add https://github.com/gombing/ISO27001Agent --skill audit-prep-gombing
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: audit-prep
Source: https://github.com/gombing/ISO27001Agent/tree/main/audit-prep
Command: npx skills add https://github.com/gombing/ISO27001Agent --skill audit-prep-gombing

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Automates Stage 1 and Stage 2 ISO 27001:2022 audit readiness by loading prior engagement documents, applying a structured readiness framework, and surfacing gaps with actionable punch lists.

Core Features & Use Cases

  • Stage 1 documentation inventory and readiness assessment against mandatory ISMS documents and SoA mappings.
  • Stage 2 implementation evidence check focusing on high-risk controls, with go/no-go recommendations.
  • Automatic Readiness Report generation including a stage-specific verdict, punch list, and a complete engagement checklist to guide remediation.
  • Supports end-to-end ISO 27001 lifecycle from client intake through to audit readiness.

Quick Start

Run the audit-prep skill to generate a readiness report from your latest engagement data.

Frequently Asked Questions about audit-prep

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare for an ISO 27001:2022 audit readiness assessment?

An ISO 27001 audit readiness assessment loads prior engagement documents to identify gaps against mandatory ISMS documents and SoA mappings. It applies a structured framework across the engagement lifecycle, outputting a Readiness Report with a go/no-go verdict and a prioritized punch list.

What is the difference between Stage 1 and Stage 2 ISO 27001 audit preparation?

Stage 1 ISO 27001 audit preparation focuses on documentation inventory and readiness assessment against mandatory ISMS documents and SoA mappings. Stage 2 preparation checks implementation evidence for high-risk controls and provides go/no-go recommendations before the final audit review.

How do I generate an ISO 27001 audit punch list from existing engagement documents?

To generate an audit punch list, load your existing engagement documents from the ./engagements directory and run a structured readiness assessment. The skill automatically surfaces gaps and outputs a formatted Markdown Readiness Report containing a prioritized punch list for auditor review.

Do I need a specific control checklist to assess ISO 27001 audit readiness?

Yes, you need a defined control checklist to rate items and assess ISO 27001 audit readiness. The skill requires this checklist alongside access to your ./engagements directory to evaluate documentation and evidence, producing a formatted Markdown Readiness Report with a stage-specific verdict.

Can I evaluate ISO 27001 implementation evidence for high-risk controls before the audit?

Yes, evaluating ISO 27001 implementation evidence for high-risk controls is a core feature of Stage 2 audit preparation. The skill checks this evidence against your defined control checklist and provides specific go/no-go recommendations to determine if you are ready for auditor review.

What format does the ISO 27001 audit readiness report use for auditor review?

The ISO 27001 audit readiness report uses a formatted Markdown structure suitable for auditor review. It includes a stage-specific go/no-go verdict, a prioritized punch list of identified gaps, and a complete engagement checklist to guide your remediation efforts.