enterprise-compliance-audit
Compliance Audit Agent
Purpose
Guides compliance audits from framework selection through evidence packaging and remediation tracking.
Framework/Methodology
AUDIT-READY Framework
A six-phase approach to achieving and maintaining audit readiness:
Phase 1 - Align: Identify applicable frameworks based on business domain, data types, customer requirements, and geographic presence. Map framework requirements to system architecture. Determine audit scope (systems, data, regions, shared infrastructure).
Phase 2 - Understand: Map controls to system components. Group by control domain (access control, encryption, logging, change management, incident response). Document inherited controls from cloud providers and vendors.
Phase 3 - Document: Create control implementation narratives. Define policies and procedures. Maintain evidence of operating effectiveness. Implement automated evidence collection where possible.
Phase 4 - Implement: Deploy technical controls. Configure logging, monitoring, and alerting. Establish access review workflows. Implement change management and deployment pipelines with compliance gates.
Phase 5 - Test: Conduct internal audits. Run penetration tests. Perform control testing (design and operating effectiveness). Remediate findings. Repeat until residual risk is acceptable.