Agent skill

Audit Remediation Program

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Guides audit findings remediation program management including finding prioritization by severity (critical, high, medium, low), owner assignment, remediation planning, deadline tracking…

Apache-2.0Auto-check passedLegal & Compliance

Install Audit Remediation Program

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill audit-remediation-program -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills audit-remediation-program --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/audit-remediation-program .claude/skills/audit-remediation-program && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-remediation-program
GitHub stars
297
Token cost
~5.3k tokens
SKILL.md length
2,012 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides audit findings remediation program management including finding prioritization by severity (critical, high, medium, low), owner assignment, remediation planning, deadline tracking…

  • Works in 4 steps: Audit Issues Finding: The audit source… → DPO Registers Finding: The DPO (or… → Initial Triage Meeting (within 3… → …
  • Tasks that involve Audit readiness
  • SKILL.md covers Overview, Finding Lifecycle, Finding Prioritization and Owner Assignment, plus 6 more sections
  • Runs Python scripts from its folder

What it does

Audit Remediation Program is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides audit findings remediation program management including finding prioritization by severity (critical, high, medium, low), owner assignment, remediation planning, deadline tracking, verification testing, closure criteria, escalation protocols, and management reporting. Covers remediation lifecycle from finding issuance to verified closure. Keywords: audit remediation, finding management, prioritization, verification testing, closure criteria, remediation tracking.

Its SKILL.md is about 5.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Audit readiness, Prioritization frameworks and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Audit readiness
  • Tasks that involve Prioritization frameworks
  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the audit-remediation-program skill to guide audit findings remediation program management including finding prioritization by severity…”
  • “/audit-remediation-program”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Audit Issues Finding: The audit source (internal audit, external auditor, DPA) documents the finding
  2. DPO Registers Finding: The DPO (or finding management coordinator) registers the finding in the tracking system
  3. Initial Triage Meeting (within 3 business days of registration)
  4. Verification Owner Assignment: Determined by finding source

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Remediation Program loads about 5.3k tokens when it runs, and up to ~6.6k if it reads all its reference files. Until then it costs about 125 tokens; SKILL.md has 2,012 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~125
When it runs · the whole SKILL.md, loaded when a task matches
~5.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,012 words, ~5,332 tokens.

Download SKILL.mdSave it as .claude/skills/audit-remediation-program/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
audit-remediation-program
description
Guides audit findings remediation program management including finding prioritization by severity (critical, high, medium, low), owner assignment, remediation planning, deadline tracking, verification testing, closure criteria, escalation protocols, and management reporting. Covers remediation lifecycle from finding issuance to verified closure. Keywords: audit remediation, finding management, prioritization, verification testing, closure criteria, remediation tracking.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
privacy-audit-certification
metadata.tags
audit-remediation, finding-management, prioritization, verification, closure-criteria

Audit Findings Remediation Program

Overview

An audit findings remediation program ensures that privacy audit findings — whether from internal audits, external audits (SOC 2, ISO 27701), regulatory inspections, or self-assessments — are systematically prioritized, assigned, tracked, remediated, verified, and closed. Without a structured remediation program, findings accumulate as "privacy debt," increasing regulatory risk and undermining the credibility of the privacy program.

The remediation program operates as a closed-loop system: findings enter the pipeline, are triaged and assigned, remediated by control owners, verified by the audit function (or an independent party), and formally closed only when evidence confirms effective remediation. Findings that fail verification are reopened with revised remediation plans and escalated if they become overdue.

Sentinel Compliance Group manages an average of 85 open privacy findings per year across internal audits (47), SOC 2 examinations (12), ISO 27701 audits (8), regulatory inquiries (6), and self-assessment activities (12), with a 91% on-time remediation rate in 2024.

Finding Lifecycle

Finding Issued by Audit Source
  ↓
Finding Registered in Tracking System
  ↓
Initial Triage (severity classification, regulatory impact)
  ↓
Owner Assignment (finding owner + remediation owner)
  ↓
Management Response Due (10 business days)
  ↓
Remediation Plan Approved
  ↓
Remediation In Progress
  ↓
Remediation Owner Reports Completion
  ↓
Verification Testing by Audit/Independent Party
  ↓
Pass → Finding Closed with Evidence → Archived
  ↓
Fail → Finding Reopened → Revised Remediation Plan → Escalation if Overdue

Finding Prioritization

Severity Classification
SeverityCriteriaRemediation DeadlineEscalation Timeline
CriticalSystemic regulatory non-compliance; active or imminent data exposure; processing without lawful basis for large-scale activity; complete control failure affecting data subject rights30 calendar daysDay 1: CPO + CISO notified; Day 5: CEO notified if no plan; Day 15: Board notified if no progress
HighMaterial non-compliance with specific GDPR article; control design deficiency; widespread operating failure; regulatory inspection finding60 calendar daysDay 10: CPO notified if no plan; Day 30: CEO notified if behind schedule; Day 45: Audit Committee notified
MediumIsolated non-compliance; control operating inconsistently; documentation gaps with compliance implications; process improvement needed for compliance90 calendar daysDay 30: CPO notified if no plan; Day 60: Escalate to management
LowMinor documentation gaps; best practice deviations; control enhancements; efficiency improvements180 calendar daysDay 90: Follow-up notification; Day 150: Escalate to management
AdvisoryRecommendations for enhancement; emerging risk observations; no current non-compliance identifiedNo mandatory deadlineTracked for information; reviewed during next audit cycle
Multi-Factor Prioritization

Beyond severity, findings are prioritized using additional factors:

FactorWeightScoring (1-5)
Severity40%1 = Advisory, 2 = Low, 3 = Medium, 4 = High, 5 = Critical
Regulatory Exposure20%1 = No regulatory linkage, 5 = Direct GDPR article non-compliance with enforcement precedent
Data Subject Impact15%1 = No impact, 5 = Direct harm to data subjects (breach, rights denial)
Systemic Risk10%1 = Isolated occurrence, 5 = Affects multiple processes/systems/locations
Recurrence10%1 = First occurrence, 5 = Finding repeated 3+ times
External Visibility5%1 = Internal only, 5 = Visible to regulators/customers/public

Priority Score: Weighted sum (maximum 5.0)

Score RangePriority TierQueue Position
4.0 — 5.0Tier 1Immediate attention; reviewed daily
3.0 — 3.9Tier 2Active management; reviewed weekly
2.0 — 2.9Tier 3Standard tracking; reviewed monthly
1.0 — 1.9Tier 4Periodic tracking; reviewed quarterly

Owner Assignment

Role Definitions
RoleResponsibilityAccountability
Finding OwnerSenior leader accountable for remediation outcomes; typically the department head or VP whose area is affectedEnsures resources, removes blockers, approves remediation plan, accountable for deadline compliance
Remediation OwnerIndividual responsible for executing the remediation plan; typically a manager or team leadDevelops remediation plan, executes remediation activities, reports progress, provides evidence of completion
Verification OwnerIndividual responsible for testing that remediation is effective; typically internal audit or an independent partyDesigns verification tests, executes testing, determines pass/fail, documents results
Escalation OwnerSenior leader responsible for resolving escalated findings; typically CPO or CISOIntervenes when findings are overdue, allocates additional resources, reports to executive management
Assignment Process
  1. Audit Issues Finding: The audit source (internal audit, external auditor, DPA) documents the finding
  2. DPO Registers Finding: The DPO (or finding management coordinator) registers the finding in the tracking system
  3. Initial Triage Meeting (within 3 business days of registration):
    • Privacy team reviews the finding for severity classification
    • Identifies the organizational area responsible
    • Assigns Finding Owner based on organizational accountability
    • Finding Owner designates Remediation Owner within 5 business days
  4. Verification Owner Assignment: Determined by finding source:
    • Internal audit findings → Internal audit team verifies
    • External audit findings → External auditor verifies at next examination, or internal audit verifies earlier
    • DPA findings → DPO verifies with legal review
    • Self-assessment findings → Internal audit or peer review

Remediation Planning

Management Response (Due Within 10 Business Days)

The Finding Owner must provide a formal management response:

Finding ID: RA-2025-017
Finding Title: Incomplete vendor sub-processor notification
Severity: High
Finding Source: Internal Privacy Audit PA-2025-Q1

MANAGEMENT RESPONSE

Response Date: 2025-02-15
Finding Owner: VP, Procurement — Sarah Chen
Remediation Owner: Senior Vendor Manager — James Park

Agree/Disagree: Agree

Root Cause Analysis:
  The current vendor management process does not include a mandatory step for
  vendors to provide updated sub-processor lists when changes occur. The DPA
  template includes a sub-processor notification clause (Section 8.3), but
  there is no operational workflow to receive, review, and action these
  notifications. 14 of 47 active processor DPAs were found to have outdated
  sub-processor lists during the audit period.

Remediation Plan:
  1. Implement sub-processor change notification workflow in vendor management
     platform (ServiceNow) — target: March 15, 2025
  2. Send outreach to all 47 processors requesting current sub-processor lists
     — target: March 1, 2025
  3. Update DPA template to include specific notification timeframe (30 days
     prior notice) and objection mechanism — target: March 15, 2025
  4. Establish quarterly sub-processor list verification for high-risk vendors
     — target: April 1, 2025
  5. Deliver training to procurement team on sub-processor change management
     — target: March 31, 2025

Target Completion Date: April 1, 2025
Resources Required: 40 hours procurement team time; ServiceNow configuration
  (IT support ticket submitted)
Dependencies: ServiceNow workflow configuration by IT (estimated 2 weeks)

Interim Risk Mitigation:
  Immediate outreach to the 14 vendors with outdated lists to obtain current
  sub-processor information; manual tracking via spreadsheet until ServiceNow
  workflow is operational.
Remediation Plan Quality Criteria

A remediation plan is approved only if it meets these criteria:

CriterionRequirement
Root Cause AddressedPlan addresses the underlying cause, not just the symptom
Specific ActionsEach action is concrete, measurable, and assignable
Realistic TimelineDeadlines are achievable given dependencies and resource constraints
Resource IdentifiedPersonnel, budget, and tools required are identified
Dependencies DocumentedExternal dependencies (IT, legal, vendor) are identified with contingency
Interim MitigationIf the finding presents immediate risk, interim measures are in place pending full remediation
Verifiable OutcomeThe expected end-state is described in terms that can be objectively tested
Owner AssignedEach action has a named individual responsible

Plans that do not meet these criteria are returned for revision within 5 business days.

Deadline Tracking

Tracking System Requirements

The finding tracking system must support:

CapabilityPurpose
Unique finding IDConsistent reference across all communications
Status trackingOpen, In Progress, Pending Verification, Closed, Reopened
Severity classificationCritical, High, Medium, Low, Advisory
Date trackingRegistration date, management response date, target date, actual completion date, verification date, closure date
Owner assignmentFinding owner, remediation owner, verification owner
Evidence attachmentUpload evidence of remediation and verification
Automated notificationsReminders at 50%, 75%, 90% of deadline; overdue alerts
Reporting and dashboardsStatus summaries by severity, age, owner, source
Audit trailComplete history of all changes, communications, and status transitions
Status Definitions
StatusDefinitionTransition Criteria
NewFinding registered; not yet triaged→ In Progress: after triage and owner assignment
In ProgressRemediation plan approved; work underway→ Pending Verification: remediation owner reports completion with evidence
Pending VerificationRemediation reported complete; awaiting verification testing→ Closed: verification passes; → Reopened: verification fails
ClosedVerification passed; finding archivedTerminal status (can be reopened if issue recurs)
ReopenedVerification failed or issue recurred→ In Progress: revised remediation plan submitted
OverduePast target date without completionTriggers escalation per severity level
Risk AcceptedManagement formally accepts the risk of not remediatingRequires CPO + CISO approval for High; Board approval for Critical
Automated Notification Schedule
TriggerNotificationRecipients
Finding registeredAssignment notificationFinding Owner, Remediation Owner
Management response due in 3 daysReminderFinding Owner
Management response overdueEscalationFinding Owner, CPO
50% of remediation deadline elapsedProgress checkRemediation Owner
75% of remediation deadline elapsedUrgency reminderRemediation Owner, Finding Owner
90% of remediation deadline elapsedFinal reminderRemediation Owner, Finding Owner, CPO
Deadline passed (overdue)Overdue alertFinding Owner, CPO, Escalation Owner
Overdue by 30+ daysExecutive escalationCEO, Audit Committee (for High/Critical)
Verification completeClosure notificationAll stakeholders

Verification Testing

Verification Approaches
ApproachWhen UsedDescription
Documentation ReviewPolicy/procedure remediationVerify that updated documents exist, are approved, published, and accessible
Technical TestingSystem/configuration remediationIndependently verify that technical controls are configured as claimed
Transaction TestingProcess remediationTest a sample of transactions to verify the process now operates correctly
InterviewTraining/awareness remediationInterview personnel to verify knowledge and process adherence
ObservationProcess remediationObserve the remediated process in operation
ReperformanceControl operation remediationIndependently execute the control to verify it produces the expected result
Show full SKILL.md (807 more words)Show less
Verification Test Design

For each finding, the verification owner designs specific tests:

Finding ID: RA-2025-017
Finding Title: Incomplete vendor sub-processor notification
Verification Tests:

Test 1: ServiceNow Workflow Verification
  Procedure: Submit a test sub-processor change notification through the
  ServiceNow workflow; verify that it routes to the correct reviewer,
  generates the expected notifications, and creates an audit trail.
  Pass Criteria: Notification received by vendor manager within 1 business
  day; review completed and documented; audit trail complete.

Test 2: Sub-Processor List Currency
  Procedure: Select 10 processors from the vendor register; verify that
  sub-processor lists are current (dated within the last 90 days).
  Pass Criteria: 10 of 10 processors have current sub-processor lists.

Test 3: DPA Template Update
  Procedure: Review updated DPA template Section 8.3; verify inclusion of
  30-day prior notification requirement and objection mechanism.
  Pass Criteria: Clause present, legally reviewed, and approved.

Test 4: Procurement Team Knowledge
  Procedure: Interview 3 procurement team members on sub-processor change
  management process.
  Pass Criteria: All 3 can describe the process correctly.

Test 5: Quarterly Review Process
  Procedure: Verify that the quarterly sub-processor review is scheduled
  and that the first review has been completed for high-risk vendors.
  Pass Criteria: Review schedule established; first review completed with
  documented results.
Verification Outcomes
OutcomeCriteriaNext Step
PassAll verification tests passFinding closed with evidence archived
Partial PassSome tests pass, minor gaps remainFinding remains open; targeted remediation for remaining gaps; re-verification within 30 days
FailMaterial tests fail; remediation is ineffectiveFinding reopened; revised remediation plan required within 10 business days; escalation triggered

Closure Criteria

A finding may be closed only when ALL of the following criteria are met:

#Closure CriterionVerified By
1Remediation actions completed as documented in the approved planRemediation Owner attestation
2Verification testing passed with documented resultsVerification Owner
3Evidence of remediation attached to the finding recordVerification Owner review
4Root cause addressed (not just symptom)Verification Owner assessment
5No new issues introduced by the remediationVerification Owner
6Finding Owner confirms remediation meets expectationsFinding Owner sign-off
7Closure approved by finding management coordinatorDPO or designee
Risk Acceptance (Alternative to Remediation)

In exceptional cases, management may accept the risk rather than remediate:

SeverityApproval AuthorityRequirements
LowCPOWritten justification; risk documented in risk register; annual review
MediumCPO + CISOWritten justification with risk quantification; risk register entry; semi-annual review; compensating controls documented
HighCPO + CISO + CLOBoard notification; written justification with legal opinion; risk register entry; quarterly review; compensating controls verified
CriticalNot eligible for risk acceptanceMust be remediated; Board may approve interim risk acceptance for maximum 90 days while remediation is in progress

Management Reporting

Monthly Remediation Dashboard (Privacy Operations)
MetricCurrentPrior MonthTrend
Total Open Findings2327Improving
— Critical00Stable
— High34Improving
— Medium1113Improving
— Low910Improving
New Findings This Month46Improving
Findings Closed This Month85Improving
Overdue Findings23Improving
On-Time Closure Rate (YTD)91%89%Improving
Average Days to Close4247Improving
Findings Reopened10Monitoring
Risk Accepted11Stable
Quarterly Executive Report

Content:

  1. Finding Volume and Trend: New findings, closed findings, net change by severity
  2. Overdue Analysis: Count and root cause of overdue findings; escalation actions taken
  3. Aging Analysis: Distribution of open findings by age bucket (0-30, 31-60, 61-90, 90+ days)
  4. Source Analysis: Findings by audit source (internal, SOC 2, ISO 27701, DPA, self-assessment)
  5. Theme Analysis: Common finding themes and systemic issues
  6. Remediation Effectiveness: First-time pass rate at verification; recurrence rate
  7. Risk Acceptances: Active risk acceptances with next review dates
  8. Forecast: Expected finding volume and closure trajectory for next quarter
Annual Remediation Program Review

Content:

  1. Total findings managed during the year (opened, closed, carried forward)
  2. On-time remediation rate by severity and source
  3. Average remediation time by severity
  4. Verification pass rate (first attempt)
  5. Recurrence analysis: findings that reappear from prior years
  6. Root cause trends: top 5 root causes across all findings
  7. Program maturity assessment: improvements to the remediation program itself
  8. Recommendations for the following year

Integration with Audit Cycle

Internal Audit Integration
  • Internal audit findings flow directly into the remediation tracking system upon report issuance
  • Internal audit conducts verification testing for its own findings
  • Internal audit reports remediation status in its quarterly report to the Audit Committee
  • Findings from prior audits are followed up during subsequent audits
External Audit Integration
  • SOC 2 exceptions are registered as findings upon report receipt
  • ISO 27701 nonconformities are registered upon audit report issuance
  • External auditors may accept internal remediation evidence at subsequent examinations
  • Timing: align remediation completion with external audit cycles to demonstrate closure
Regulatory Finding Integration
  • DPA findings, recommendations, and orders are registered immediately upon receipt
  • Legal review of all regulatory findings before remediation plan development
  • DPO tracks regulatory finding remediation separately with expedited timelines
  • Evidence of remediation is prepared for potential DPA follow-up

Sentinel Compliance Group Remediation Program

  • Tracking System: ServiceNow GRC module with custom privacy finding workflow
  • 2024 Volume: 85 findings managed (47 internal audit, 12 SOC 2, 8 ISO 27701, 6 DPA inquiry, 12 self-assessment)
  • Closure Results: 78 closed within target date (91%); 5 closed with extension; 2 risk-accepted
  • Average Remediation Time: Critical: 18 days (target: 30); High: 41 days (target: 60); Medium: 62 days (target: 90); Low: 98 days (target: 180)
  • Verification Pass Rate: 87% first-attempt pass rate; 13% required rework
  • Recurrence Rate: 8% (7 findings repeated from prior years)
  • Top Root Causes (2024): (1) Incomplete vendor management processes (18 findings); (2) Inadequate documentation of processing activities (14 findings); (3) Inconsistent DSAR handling across business units (11 findings); (4) Training gaps for new hires in privacy-critical roles (9 findings); (5) Technical control configuration drift (8 findings)
  • Overdue Findings at Year-End: 2 (both Medium severity, within 15 days of deadline, escalated to CPO)
  • Program Improvement for 2025: Implement automated verification testing for technical controls; integrate with continuous compliance monitoring for real-time deviation detection

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/audit-remediation-program of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Audit Remediation Program next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Remediation Program compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Remediation Program this skillmukul975/Privacy-Data-Protection-Skills297—~5.3kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Compliance Osalirezarezvani/claude-skills28k—~3.3kAutomated safety check: PassMIT
Implementing Complianceancoleman/ai-design-components526—~4kAutomated safety check: PassMIT
Compliance Checklistmohitagw15856/pm-claude-skills1.4k—~1.2kAutomated safety check: PassMIT
Compliance Checklist Generationseb1n/awesome-ai-agent-skills206—~2.5kAutomated safety check: PassMIT

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Compliance Os

    alirezarezvani/claude-skills

    Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…

    28k GitHub stars~3.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    526 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • Compliance Checklist

    mohitagw15856/pm-claude-skills

    Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis.

    1.4k GitHub stars~1.2k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Compliance Checklist Generation

    seb1n/awesome-ai-agent-skills

    Build evidence-oriented readiness checklists for frameworks such as SOC 2, HIPAA, PCI DSS, and GDPR, with gaps and remediation priorities.

    206 GitHub stars~2.5k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • Eu AI Act Readiness

    seb1n/awesome-ai-agent-skills

    Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…

    206 GitHub stars~3.3k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    297 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    297 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    297 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    297 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Audit Remediation Program

What does Audit Remediation Program do?

Guides audit findings remediation program management including finding prioritization by severity (critical, high, medium, low), owner assignment, remediation planning, deadline tracking…. Audit Remediation Program is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides audit findings remediation program management including finding prioritization by severity (critical, high, medium, low), owner assignment, remediation planning, deadline tracking, verification testing, closure criteria, escalation protocols, and management reporting.

When should I use Audit Remediation Program?

Audit Remediation Program fits situations like: tasks that involve Audit readiness; tasks that involve Prioritization frameworks; tasks that involve Privacy and GDPR.

How do I install Audit Remediation Program in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill audit-remediation-program -a claude-code`. Or copy the skill folder (skills/privacy/audit-remediation-program in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/audit-remediation-program in your project. Claude Code loads it when a task matches its description.

How do I install Audit Remediation Program in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill audit-remediation-program -a codex`. Or copy the skill folder (skills/privacy/audit-remediation-program in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/audit-remediation-program in your project. Codex loads it when a task matches its description.

Can I use Audit Remediation Program in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill audit-remediation-program -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-remediation-program, .gemini/skills/audit-remediation-program, .github/skills/audit-remediation-program and .opencode/skills/audit-remediation-program in your project.

What does Audit Remediation Program need to run?

Going by SKILL.md and its folder, Audit Remediation Program needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Audit Remediation Program access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit Remediation Program safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Audit Remediation Program use?

Audit Remediation Program is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Remediation Program use?

About 5.3k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Audit Remediation Program?

Skills that share tags, products or a category with Audit Remediation Program: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Compliance Os (alirezarezvani/claude-skills, 28k stars), Implementing Compliance (ancoleman/ai-design-components, 526 stars) and Compliance Checklist (mohitagw15856/pm-claude-skills, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Remediation Program?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 297 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.