Compliance & Audit Bundle | Prompeteer.ai

Audit-readiness checklists, control-narrative drafting, evidence-collection templates, and walkthrough-prep skills.

Included Skills (46)

  1. SOC 2 Assistant — Assists SaaS companies preparing for SOC 2 audits by mapping criteria, building matrices, and assessing audit readiness.
  2. Building Vulnerability Exception Tracking System — The skill builds a vulnerability exception and risk acceptance tracking system that automates approval workflows, documents compensating controls, and enforces automatic expiration for vulnerabilities that miss SLA remediation timelines. It supports governance processes for risk acceptance and exception approvals, enabling organizations to meet PCI DSS, SOC 2, or NIST CSF compliance requirements. This solution benefits security teams and compliance officers who need a streamlined, auditable method to manage and document vulnerability exceptions.
  3. ISMS Audit Assistant — This skill helps security professionals conduct ISO 27001 ISMS audits, assess controls, and prepare for certification.
  4. ISO Readiness Assistant — This tool organizes and reviews evidence for ISO management and laboratory standards to help quality managers prepare documentation for formal audits.
  5. GDPR DSAR Automator — Automates GDPR Data Subject Access Request workflows by streamlining PII discovery, identity verification, and regulatory reporting for privacy and compliance teams.
  6. Tamper-Evident Audit — Implement tamper-evident audit logs for compliance, helping developers build secure and compliant applications with immutable event tracking.
  7. Implementing Vulnerability Remediation Sla — Design a vulnerability remediation SLA program covering asset tiering,
  8. Performing Access Review And Certification — Designs and runs access review and certification campaigns-scoping,
  9. GDPR Compliance Automation — Automates GDPR compliance for web applications, assisting developers with PII auditing, consent management, and data request handling.
  10. SOC2 Compliance Assistant — Helps SaaS companies achieve SOC 2 Type II compliance by implementing controls and preparing for audits to meet enterprise requirements.
  11. Building Vulnerability Aging And Sla Tracking — The skill builds a vulnerability aging dashboard and SLA tracking system that measures time‑to‑remediation against severity‑based deadlines, such as 14 days for critical, 30 days for high, 60 days for medium, and 90 days for low. It automates escalations and generates compliance metrics reports, enabling security teams to design SLA policies, monitor aging dashboards, and demonstrate adherence to remediation timelines.
  12. Managing Third Party Vendor Risk — The skill establishes and operates a comprehensive third-party risk management program aligned with NIST SP 800-161 C-SCRM, covering vendor inventory, tiering, security assessments, contractual safeguards, and continuous monitoring. It benefits security and compliance professionals responsible for evaluating vendors, implementing risk frameworks, or negotiating secure contractual terms.
  13. Auditing Cloud With Cis Benchmarks — The skill audits AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools such as Prowler and ScoutSuite, interpreting failed controls, and tracking remediation for continuous compliance. It is used by security teams to validate CIS benchmark compliance (CIS v5 AWS, v4 Azure, v4 GCP) and to establish ongoing cloud compliance monitoring.
  14. Expense Reconciliation Auditor — This tool automates expense folder audits by reconciling receipts with bank statements, categorizing transactions, and flagging policy violations for financial controllers.
  15. CCPA Compliance Assistant — Helps businesses comply with CCPA/CPRA by implementing data privacy features and responding to consumer data requests.
  16. Implementing AWS Macie For Data Classification — The skill enables and configures Amazon Macie using AWS CLI or Terraform to discover, classify, and protect sensitive data in S3, including PII, financial data, and credentials, through machine‑learning and pattern‑matching techniques. It sets up discovery jobs, custom data identifiers, allow lists, and EventBridge‑based remediation to ensure continuous monitoring and compliance. This service benefits data security teams, compliance officers, and cloud architects who need robust S3 data classification, cloud DLP, or auditing for unprotected sensitive information.
  17. Implementing Vulnerability Sla Breach Alerting — Build an automated SLA breach alerting system for vulnerability remediation,
  18. GDPR Compliance Auditor — This tool automates GDPR and DSGVO compliance by scanning codebases for privacy risks and managing documentation for data protection assessments and subject requests.
  19. PCI DSS Compliance — Achieve PCI DSS compliance by scoping, implementing controls, and selecting SAQ types for secure payment card data handling.
  20. Cookie Consent Manager — Implements GDPR/ePrivacy-compliant cookie consent management, assisting developers in adding cookie banners and managing user consent for EU compliance.
  21. Detecting Email Account Compromise — The skill analyzes Unified Audit Logs and Azure AD sign‑in logs to detect impossible travel, inbox rule changes, external forwarding, and anomalous Microsoft Graph API or OAuth token activity. It identifies compromised O365 and Google Workspace accounts, enabling security teams to investigate business email compromise, account takeover, and malicious mailbox persistence. The tool provides actionable insights for incident responders and threat analysts.
  22. Implementing Cloud Dlp For Data Protection — Implement cloud DLP using Amazon Macie, Google Cloud DLP API, Microsoft
  23. Performing Asset Criticality Scoring For Vulns — Build a multi-factor asset criticality scoring model—incorporating data
  24. Contract Risk Analyzer — Analyzes contracts to identify risks, missing clauses, and unfavorable terms, providing actionable recommendations for users.
  25. Implementing Jwt Signing And Verification — The skill implements secure JWT signing and verification with HMAC‑SHA256, RSA‑PSS, ES256, and EdDSA, handling token expiration, claims validation, and protection against algorithm‑confusion, none‑algorithm, and key‑injection attacks. It is used to add or harden JWT‑based authentication and authorization, and to audit token verification code for common vulnerabilities.
  26. Personalization Governance Framework — This tool helps personalization teams enforce compliance, manage approval workflows, and maintain audit trails for high-impact content and model deployments.
  27. Compliance Review Orchestrator — This tool provides a standardized framework for campaign compliance intake and documentation to assist legal and medical teams in streamlining regulatory approval workflows.
  28. Implementing Cloud Security Posture Management — Continuously monitor multi-cloud environments (AWS, Azure, GCP) for
  29. Implementing AWS Config Rules For Compliance — Implements AWS Config managed and custom rules for continuous compliance
  30. Performing Cve Prioritization With Kev Catalog — Fetch and parse the CISA Known Exploited Vulnerabilities (KEV) catalog,
  31. Breach Data Checker — Checks for email or domain exposure in known data breaches using the HaveIBeenPwned API and other sources.
  32. Medical Device Auditor — This tool pressure-tests medical device quality management systems using six targeted questions to ensure regulatory compliance before audits, submissions, or product launches.
  33. ISO 42001 Auditor — This tool pressure-tests AI Management Systems against ISO 42001 standards to help compliance officers prepare for certification audits and internal reviews.
  34. Building Role Mining For Rbac Optimization — Apply bottom-up and top-down role mining techniques, including clustering
  35. Implementing Google Workspace Admin Security — Hardens a Google Workspace tenant via Admin Console configuration:
  36. Implementing Infrastructure As Code Security Scanning — Implements automated security scanning for Infrastructure as Code using
  37. EU AI Act Compliance Assistant — This tool assists compliance teams in navigating EU AI Act regulations by classifying system risk tiers, determining conformity assessment routes, and tracking organizational obligations.
  38. Implementing Dmarc Dkim Spf Email Security — The skill configures SPF, DKIM, and DMARC DNS TXT records to authenticate outbound email, preventing domain spoofing and enforcing rejection or quarantine of unauthenticated mail. It also audits a domain’s current DNS state to identify gaps. Domain owners and security teams use it to harden email security and defend against phishing and spoofing attacks.
  39. Implementing Immutable Backup With Restic — Implements ransomware-resistant backups using restic with S3-compatible
  40. Detecting Insider Threat Behaviors — Detect insider threat behavioral indicators including unusual data access,
  41. Implementing Aes Encryption For Data At Rest — The skill guides the implementation of AES‑256 in GCM mode for files and data stores at rest, detailing key derivation, IV/nonce management, and authenticated encryption. It is used by security engineers and compliance officers to configure encryption controls that satisfy regulatory standards. The guide also supports auditors reviewing an implementation during a security assessment.
  42. Agent Action Notary — This tool generates tamper-evident, post-quantum-signed receipts for autonomous agent actions, helping developers ensure accountability and compliance with regulatory record-keeping requirements.
  43. NIST RMF Compliance — This skill guides federal system owners through the NIST RMF process to achieve and maintain an Authorization to Operate for cybersecurity compliance.
  44. Detecting Business Email Compromise — Detect Business Email Compromise (BEC) fraud, where attackers impersonate
  45. Detecting Insider Threat With Ueba — Implement User and Entity Behavior Analytics (UEBA) using Elasticsearch/OpenSearch
  46. Participant Operations Manager — This skill streamlines participant recruitment, scheduling, compliance, and incentive fulfillment to help researchers manage study logistics efficiently and securely.