audit-evidence
Installation
SKILL.md
Audit Evidence Collector
Disclaimer: this skill covers operational evidence collection. Legal holds, forensics-grade chain of custody for legal proceedings, and legal evidentiary weight require separate expertise (forensics-assist/legal). This skill targets compliance-audit-grade evidence.
When to use
Every audit runs on evidence. Compliance frameworks are the "what must you"; this skill is the "how do you prove it". It is the counterpart of what iso27001 phase 5 and soc2 phase 4 ask for: a systematic collection an auditor can consume without six weeks of back-and-forth questions.
Triggers on:
- A question like "how do we collect evidence for SOC 2 Type II", "what is control evidence", "evidence packaging for the auditor", "chain of custody for audit", "set up automated evidence collection", "how long do we keep audit evidence".
- Preparation for an external audit: SOC 2, ISO 27001 Stage 2, PCI-DSS, internal audit per ISMS Cl 9.2.
- A handoff from
iso27001,soc2,nis2,dorawhere evidence requirements need to be operationalized. - A vendor-security review that asks for evidence output toward customers (see
vendor-questionnairereceiver mode). - A post-incident review where evidence on controls must be reconstructed.