PBC and request-list tracking
Map a client's uploaded folder against the request list to see what is genuinely satisfied before you start testing.
— Risk & Compliance
Maps an uploaded evidence set against a list of assertions or PBC items to produce a coverage matrix, flagging unsupported assertions and orphaned documents.
1 week → ~10 minutes
For a typical multi-document review workflow
No coding required
— USE CASES
Map a client's uploaded folder against the request list to see what is genuinely satisfied before you start testing.
Establish coverage per assertion so fieldwork time goes to the gaps rather than to re-reading complete files.
Surface stale or orphaned documents that support no assertion and can be dropped from the file.
— HOW IT BEHAVES
The mechanics behind this specific template — what it reads, what it calculates, and where a human stays in the loop.
A coverage pass shows what is supported and what is not — including requirements with nothing behind them and material that supports nothing.
A folder of material is processed as one set, so cross-document patterns surface instead of being read one file at a time.
Findings are written up as a document that reads like professional output rather than raw model text.
The slow part of fieldwork is proving which document supports which assertion. PBC and request-list tracking is the typical trigger — map a client's uploaded folder against the request list to see what is genuinely satisfied before you start testing. Done properly it is defensible; done at pace it becomes a judgement call nobody can retrace. And "properly" usually means 1 week of manual work.
As a Skill, the work is already sequenced. You bring the evidence, and the run produces a document-by-assertion coverage matrix plus a named list of unsupported assertions. What sits between input and output is the codified method: thresholds, sequencing and the points where a human confirms a call — all of it visible and editable in the Skill. The practical effect: 1 week of manual work becomes a ~10 minutes run, held to an identical standard on the tenth engagement as on the first.
Audit evidence mapping exports as a structured SKILL.md file and is MCP-ready, so the same method runs in ChatGPT, Claude, Copilot or your own AI products. Adapt it to your methodology, and the intelligence stays yours — not locked to one vendor.
Regulation scan
Researches regulatory change in a defined area, classifies the findings, and states the implications for your specific business context.
Control gap assessment (SOC 2 / ISO 27001)
Extracts documented controls and framework requirements, then grades every requirement covered, partial or absent for SOC 2 or ISO 27001 readiness.
RCSA questionnaire → risk register
Runs a scored risk and control self-assessment questionnaire and calculates residual risk identically every time, producing a register comparable across teams and quarters.