PBC and request-list tracking
Map a client's evidence folder against the request list to see what is genuinely satisfied before you start testing.
— Risk & Compliance
Pairs a full evidence set against every audit assertion or PBC item to produce a coverage matrix, naming the assertions nothing supports and the documents supporting nothing.
2–3 days → ~10 minutes
For a typical multi-document review workflow
No coding required
— USE CASES
Map a client's evidence folder against the request list to see what is genuinely satisfied before you start testing.
Establish coverage per assertion so fieldwork time goes to the gaps rather than to re-reading complete files.
Surface stale or orphaned documents that support no assertion and can be dropped from the file.
— HOW IT BEHAVES
The mechanics behind this specific template — what it reads, what it calculates, and where a human stays in the loop.
A coverage pass shows which risks are supported by evidence and which are not — including requirements with nothing behind them and material that supports nothing.
All of your risk registers, controls and policy documents is processed as one set, so patterns across documents surface instead of being read one file at a time.
Findings on the risk universe in scope are written up as a document that reads like professional output, with each claim tied back to a risk.
The slow part of fieldwork is proving which document supports which assertion. PBC and request-list tracking is the typical trigger — map a client's evidence folder against the request list to see what is genuinely satisfied before you start testing. Done properly it is defensible; done at pace it becomes a judgement call nobody can retrace. And "properly" usually means 2–3 days of manual work.
As a Skill, the work is already sequenced. You bring the evidence, and the run produces a document-by-assertion coverage matrix plus a named list of unsupported assertions. What sits between input and output is the codified method: thresholds, sequencing and the points where a human confirms a call — all of it visible and editable in the Skill. The practical effect: 2–3 days of manual work becomes a ~10 minutes run, held to an identical standard on the tenth engagement as on the first.
Audit evidence mapping exports as a structured SKILL.md file and is MCP-ready, so the same method runs in ChatGPT, Claude, Copilot or your own AI products. Adapt it to your methodology, and the intelligence stays yours — not locked to one vendor.
Assesses a data subject access request end to end and returns a governed decision on whether to fulfil it, fulfil it in part, refuse it with reasons or extend the deadline, having verified identity, mapped the request to the systems that actually hold the data and held the outcome for a data protection sign-off before anything is disclosed.
Fans multiple audit or review reports into individual findings, deduplicates repeats, and sorts them by severity into one consolidated register with sources retained.
Reads a submitted claim against the policy wording that governs it and returns a coverage assessment showing whether it appears covered, potentially excluded or in need of specialist review, mapped clause by clause and never issued without a handler's sign-off.
Assesses a reported incident against your response playbook and policies, assigns the severity band the evidence supports, and returns the matching response plan with the notifications, owners and timelines that band requires.
Assesses personal-data processing and cross-border transfers against privacy policy and jurisdiction rules, producing a documented approval outcome with conditions, policy evidence and grounds for referral.
Assesses current policies, controls and supporting evidence against regulatory requirements, producing a gap assessment and prioritised remediation plan for reviewer approval.