evidence-validator

Validate audit evidence artifacts against SOC 2 and ISO 27001 control requirements.

367|83|Updated Dec 26, 2025
One-click install
npx skills add https://github.com/GRCEngClub/claude-grc-engineering --skill evidence-validator-grcengclub
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: evidence-validator
Source: https://github.com/GRCEngClub/claude-grc-engineering/tree/main/plugins/grc-auditor/skills/evidence-validator
Command: npx skills add https://github.com/GRCEngClub/claude-grc-engineering --skill evidence-validator-grcengclub

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Audit teams spend excessive time validating scattered evidence artifacts; this skill standardizes and accelerates verification against control requirements, reducing gaps and errors.

Core Features & Use Cases

  • Completeness Check: verifies evidence covers all control aspects
  • Timeliness Validation: confirms evidence is aligned with the audit period
  • Relevance Assessment: ensures evidence demonstrates the control in practice
  • Authenticity Review: identifies tampering or inconsistencies
  • Evidence Types Supported: Screenshots, Logs, Configs, Policy docs, Access reviews
  • Output: Generates a structured memo with findings, gaps, recommendations, and auditor notes

Quick Start

Provide the audit artifacts (screenshots, logs, configurations, and policies) to the evidence-validator and run it to generate a complete evidence review memo.

Frequently Asked Questions about evidence-validator

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I validate SOC 2 audit evidence artifacts against control requirements?

To validate SOC 2 audit evidence, you provide screenshots, logs, configurations, and policy documents to automate completeness, timeliness, relevance, and authenticity checks, resulting in a structured findings memo.

What is the best way to check if compliance evidence covers all control aspects?

The best way to check compliance evidence completeness is to automate verification of screenshots, logs, and policies against control requirements. This ensures all control aspects are covered and outputs a memo detailing gaps and recommendations.

How do I confirm my audit evidence is aligned with the audit period?

To confirm audit evidence is aligned with the audit period, you apply timeliness validation to your artifacts. This process verifies that timestamps and records from screenshots, logs, and configs accurately reflect the required review timeframe.

Can I review access review logs and policy docs for SOC 2 and ISO 27001 audits together?

Yes, you can review access review logs and policy docs together for SOC 2 and ISO 27001 audits. The validation process handles multiple evidence types simultaneously to assess relevance, authenticity, and completeness across governance frameworks.

Why does my audit evidence review miss inconsistencies and tampering in configuration files?

Audit evidence review misses inconsistencies and tampering when lacking standardized authenticity checks. Automating the review of configuration files and logs identifies tampering and inconsistencies, outputting a detailed memo with auditor notes and recommendations.