mova-compliance-audit
Installation
SKILL.md
Contract Skill — A ready-to-use MOVA HITL workflow. Requires the
openclaw-movaplugin.
MOVA Compliance Audit
Submit an organization's documents to MOVA for automated regulatory compliance audit — with framework-specific rule matching, a structured findings report, and a mandatory human sign-off gate backed by a tamper-proof audit trail.
What it does
- Document ingestion — OCR extraction and structure parsing from uploaded file or URL
- Rules engine check — automated evaluation against the selected regulatory framework (GDPR, PCI-DSS, ISO 27001, SOC 2)
- Findings report — checklist with pass/fail items, severity codes, and recommended remediation actions
- Human gate — compliance officer reviews findings and chooses: approve / approve with conditions / reject / request corrections
- Audit receipt — every check, source, and decision is signed, timestamped, and stored in an immutable MOVA audit trail for regulatory inspection
Mandatory escalation rules enforced by policy:
- Critical findings present → mandatory human review, cannot auto-approve
- Regulated framework (GDPR, PCI-DSS) → full audit report artifact required
- Rejection or conditions → remediation items must be recorded with reason