
Compliance Audit Mapper
Map security controls to frameworks and close compliance gaps
What You Can Do
You can rapidly map your security controls to major regulatory frameworks (SOC 2, ISO 27001, GDPR, HIPAA, PCI-DSS), automatically identify compliance gaps, and generate audit-ready evidence packages. The skill analyzes your control inventory against framework requirements, flags missing or inadequate controls, and produces structured documentation that accelerates compliance reviews and audit preparation.
Features
Match controls to framework requirements across SOC 2, ISO 27001, GDPR, HIPAA, PCI-DSS, and custom frameworks
Automatically surface missing or inadequately documented controls with risk severity
Create audit-ready documentation bundles with control descriptions and evidence references
View compliance status across multiple frameworks simultaneously to optimize control investments
Generate ranked action plans based on risk level and implementation effort
Structured forms for documenting control implementations and evidence locations
Calculate compliance percentage by framework and identify critical gaps
Example Output
SOC 2 Mapping Example:
| Control | CC6.1 | CC7.2 | Evidence Gap |
|---|---|---|---|
| MFA for user accounts | ✓ Satisfied | ✓ Satisfied | Needs test evidence |
| Encrypted backups | ✓ Satisfied | ✗ Missing | Document encryption standard |
| Quarterly access reviews | ✓ Satisfied | — | Complete for CC6.1 only |
Gap Analysis:
- CC7.3 Restricted physical access: No current control → High priority
- CC9.2 Change management: Documented but not fully tested → Medium priority
Evidence Package Summary:
- 8/12 SOC 2 criteria have strong evidence
- 3 criteria need additional documentation
- 1 criterion requires new control implementation
What's Included
- SKILL.md: The core compliance mapping skill with decision logic
- Control Mapping Template: Pre-built frameworks (SOC 2, ISO 27001, GDPR, HIPAA, PCI-DSS) with requirement lists
- Gap Analysis Checklist: Structured questions to evaluate control sufficiency
- Evidence Package Template: Audit-ready documentation format with control descriptions and evidence references
- Remediation Prioritization Worksheet: Risk/effort matrix for planning compliance improvements
- Audit Readiness Workflow: Step-by-step guide for preparing controls for third-party review
Who It's For
- Compliance Officers — Map controls and prepare for regulatory audits or certifications
- Internal Auditors — Assess control effectiveness against framework requirements
- Security Risk Managers — Identify compliance gaps and prioritize remediation
- Audit Consultants — Help clients structure evidence for third-party reviews
- GRC Managers — Plan governance, risk, and compliance improvements
Best For
- Control-to-framework mapping — Quickly determine which existing controls satisfy specific regulatory requirements
- Audit preparation — Organize evidence and identify gaps before formal compliance reviews
- Gap analysis — Discover missing or inadequate controls across multiple frameworks
- Multi-framework compliance — Maintain SOC 2, ISO 27001, GDPR, and HIPAA simultaneously
- Remediation planning — Prioritize which gaps to close first based on risk and effort







