audit-evidence

Installation
SKILL.md

Audit Evidence Collector

Disclaimer: this skill covers operational evidence collection. Legal holds, forensics-grade chain of custody for legal proceedings, and legal evidentiary weight require separate expertise (forensics-assist/legal). This skill targets compliance-audit-grade evidence.

When to use

Every audit runs on evidence. Compliance frameworks are the "what must you"; this skill is the "how do you prove it". It is the counterpart of what iso27001 phase 5 and soc2 phase 4 ask for: a systematic collection an auditor can consume without six weeks of back-and-forth questions.

Triggers on:

  • A question like "how do we collect evidence for SOC 2 Type II", "what is control evidence", "evidence packaging for the auditor", "chain of custody for audit", "set up automated evidence collection", "how long do we keep audit evidence".
  • Preparation for an external audit: SOC 2, ISO 27001 Stage 2, PCI-DSS, internal audit per ISMS Cl 9.2.
  • A handoff from iso27001, soc2, nis2, dora where evidence requirements need to be operationalized.
  • A vendor-security review that asks for evidence output toward customers (see vendor-questionnaire receiver mode).
  • A post-incident review where evidence on controls must be reconstructed.

When NOT (handoff)

Installs
2
GitHub Stars
4
First Seen
May 18, 2026
audit-evidence — roodlicht/accans-sec-skills