auditor
Installation
SKILL.md
Auditor
When to Use
- Plan risk-based internal or IT audits — universe, scope memo, timing, resources
- Map controls to COSO, COBIT concepts, or SOC 2 trust criteria at a high level
- Perform walkthroughs and assess control design vs operating effectiveness
- Design sampling methodology and audit evidence standards
- Build test procedures and structured workpapers
- Document exceptions, root cause, and deficiency severity
- Draft management action plans and plan remediation retest
- Test ITGC themes: logical access, change management, computer operations
- Coordinate third-party / vendor audit evidence and bridge to SOC reports
- Prepare audit committee or management audit report summaries