compliance-audit

Maps regulatory controls to evidence and identifies MET, PARTIAL, or GAP statuses.

Updated Apr 1, 2026
One-click install
npx skills add https://github.com/hpsgd/turtlestack --skill compliance-audit-hpsgd
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: compliance-audit
Source: https://github.com/hpsgd/turtlestack/tree/main/plugins/leadership/grc-lead/skills/compliance-audit
Command: npx skills add https://github.com/hpsgd/turtlestack --skill compliance-audit-hpsgd

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Audit compliance against regulatory frameworks by identifying gaps, collecting evidence, and planning remediation in a structured, repeatable manner.

Core Features & Use Cases

  • Framework identification and scoping for regulatory audits (GDPR, SOC 2, ISO 27001, etc.)
  • Evidence collection, evidence mapping to controls, and status tracking (MET/PARTIAL/GAP)
  • Remediation planning, risk ranking, and audit reporting across systems and processes
  • Use Case: Compliance teams map controls, collect evidence, and generate remediation plans to maintain certifications and regulatory readiness.

Quick Start

Initiate an audit by selecting a framework, scope, and data sources, then run Compliance Audit to generate a gap report.

Frequently Asked Questions about compliance-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a regulatory compliance audit and identify gaps in my controls?

A regulatory compliance audit identifies applicable frameworks and maps existing policies and configurations to controls, determining MET, PARTIAL, or GAP statuses to produce a structured evidence plan and remediation priorities.

What is control mapping and how does it work for frameworks like GDPR and SOC 2?

Control mapping for frameworks like GDPR and SOC 2 connects existing policies and system configurations to specific regulatory requirements, evaluating evidence to determine if control statuses are MET, PARTIAL, or GAP.

Can I use this approach to audit compliance across multiple systems and processes?

Yes, compliance audits map controls and collect evidence across multiple systems and processes in scope, generating a structured gap report and remediation priorities for risk management workflows.

What's the best way to plan remediation after finding compliance gaps?

The best way to plan remediation for compliance gaps is to produce a structured evidence plan that risk-ranks identified deficiencies, prioritizing remediation actions for integration into risk management workflows.

Do I need existing policies and configurations to start a regulatory audit?

Yes, a regulatory audit requires existing policies, configurations, and evidence across in-scope systems to map against applicable regulatory framework controls and accurately determine MET, PARTIAL, or GAP statuses.