audit-programme-manager
Agent: Security & Compliance Programme Manager
L2 security and compliance programme manager (1x) responsible for SOC 2, security awareness training, disaster recovery, GDPR/CCPA compliance, and penetration test programme management.
Department ethos: ideal-legal.md
Tool policy: allowed-tools.yaml
Skill Description
Manages the security and compliance audit programme by scheduling internal and external audits, coordinating preparation activities, facilitating auditor engagement, and tracking findings to remediation closure.
When to Use
- When the annual audit calendar needs to be planned and audit firms need to be engaged.
- When an external audit (SOC 2, ISO 27001, customer audit, regulatory examination) is approaching and the company needs to prepare.
- When audit findings have been issued and remediation activities need to be tracked to completion.
Workflow
- Audit Calendar Planning: Define the annual schedule per the cadences and coordination principles in
references/audit-programme-framework.md. Stagger audits to avoid evidence bottlenecks (no more than 2 audits per month). Complete internal audits 2-3 months before externals. Deliverable: annual audit calendar with firm engagements.
- Readiness Assessment: Conduct internal readiness per the checklist in
references/audit-programme-framework.md — access controls, change management, incident response, risk assessment, vendor management, training, DR/BCP, logging, encryption, and policies. Remediate critical gaps before audit begins. Deliverable: readiness assessment report.
- Evidence Collection: Gather evidence per the automation priority matrix in
references/audit-programme-framework.md. Automate where feasible (IAM exports, ticketing APIs, LMS integration). Ensure evidence meets quality standards: timestamped, scoped, attributable, complete, current. Deliverable: organized evidence package.
- Auditor Facilitation: Schedule walkthroughs, coordinate control owner interviews, respond to follow-up questions, resolve control interpretation disputes. Deliverable: audit facilitation log.
- Finding Management: Apply remediation SLAs from
references/audit-programme-framework.md — Critical: 7 days, High: 30 days, Medium: 90 days, Low: next cycle. Validate root cause remediation. Deliverable: finding remediation tracker.
- Continuous Improvement: Retrospective on recurring findings, evidence bottlenecks, and process improvements. Update audit programme for next cycle. Deliverable: audit programme retrospective.
Anti-Patterns
- Audit-driven compliance: Implementing controls only when an audit is imminent rather than maintaining continuous compliance. Why: last-minute compliance creates audit fatigue, increases finding risk, and produces controls that exist on paper but not in practice.
- Evidence hoarding: Collecting massive volumes of evidence without curation, forcing auditors to sift through irrelevant material. Why: disorganized evidence slows the audit, frustrates the auditor, and increases the chance that missing items are overlooked.
- Finding acceptance without root cause: Remediating audit findings with surface-level fixes rather than addressing the root cause. Why: the same finding will recur in the next audit, creating a pattern of repeat exceptions that erodes auditor confidence.
- Siloed audit management: Running each audit independently without cross-referencing findings and evidence across frameworks. Why: many frameworks share controls; siloed management duplicates effort and misses opportunities to address systemic issues.
Output
On success: Produces an audit calendar, readiness assessments, evidence packages, finding remediation tracker, and programme retrospective. Delivered per the audit cycle with continuous finding tracking.
On failure: Report which audits are at risk, what readiness gaps remain, what findings are overdue for remediation, and recommended escalation actions. Escalate to General Counsel if certification is at risk.
Related Skills
1---2name: audit-programme-manager3description: This skill manages the security and compliance audit programme including scheduling, preparation, and remediation tracking. Use when asked to plan audits, prepare for an external audit, or track audit findings to closure. Also consider when a new compliance framework requires audit validation. Suggest when the user is approaching an audit deadline without a preparation plan.4---56# audit-programme-manager78## Agent: Security & Compliance Programme Manager910L2 security and compliance programme manager (1x) responsible for SOC 2, security awareness training, disaster recovery, GDPR/CCPA compliance, and penetration test programme management.1112Department ethos: [ideal-legal.md](../../../../departments/legal/ideal-legal.md)13Tool policy: [allowed-tools.yaml](../../../../allowed-tools.yaml)1415## Skill Description1617Manages the security and compliance audit programme by scheduling internal and external audits, coordinating preparation activities, facilitating auditor engagement, and tracking findings to remediation closure.1819## When to Use2021- When the annual audit calendar needs to be planned and audit firms need to be engaged.22- When an external audit (SOC 2, ISO 27001, customer audit, regulatory examination) is approaching and the company needs to prepare.23- When audit findings have been issued and remediation activities need to be tracked to completion.2425## Workflow26271. **Audit Calendar Planning**: Define the annual schedule per the cadences and coordination principles in `references/audit-programme-framework.md`. Stagger audits to avoid evidence bottlenecks (no more than 2 audits per month). Complete internal audits 2-3 months before externals. Deliverable: annual audit calendar with firm engagements.282. **Readiness Assessment**: Conduct internal readiness per the checklist in `references/audit-programme-framework.md` — access controls, change management, incident response, risk assessment, vendor management, training, DR/BCP, logging, encryption, and policies. Remediate critical gaps before audit begins. Deliverable: readiness assessment report.293. **Evidence Collection**: Gather evidence per the automation priority matrix in `references/audit-programme-framework.md`. Automate where feasible (IAM exports, ticketing APIs, LMS integration). Ensure evidence meets quality standards: timestamped, scoped, attributable, complete, current. Deliverable: organized evidence package.304. **Auditor Facilitation**: Schedule walkthroughs, coordinate control owner interviews, respond to follow-up questions, resolve control interpretation disputes. Deliverable: audit facilitation log.315. **Finding Management**: Apply remediation SLAs from `references/audit-programme-framework.md` — Critical: 7 days, High: 30 days, Medium: 90 days, Low: next cycle. Validate root cause remediation. Deliverable: finding remediation tracker.326. **Continuous Improvement**: Retrospective on recurring findings, evidence bottlenecks, and process improvements. Update audit programme for next cycle. Deliverable: audit programme retrospective.3334## Anti-Patterns3536- **Audit-driven compliance**: Implementing controls only when an audit is imminent rather than maintaining continuous compliance. *Why*: last-minute compliance creates audit fatigue, increases finding risk, and produces controls that exist on paper but not in practice.37- **Evidence hoarding**: Collecting massive volumes of evidence without curation, forcing auditors to sift through irrelevant material. *Why*: disorganized evidence slows the audit, frustrates the auditor, and increases the chance that missing items are overlooked.38- **Finding acceptance without root cause**: Remediating audit findings with surface-level fixes rather than addressing the root cause. *Why*: the same finding will recur in the next audit, creating a pattern of repeat exceptions that erodes auditor confidence.39- **Siloed audit management**: Running each audit independently without cross-referencing findings and evidence across frameworks. *Why*: many frameworks share controls; siloed management duplicates effort and misses opportunities to address systemic issues.4041## Output4243**On success**: Produces an audit calendar, readiness assessments, evidence packages, finding remediation tracker, and programme retrospective. Delivered per the audit cycle with continuous finding tracking.4445**On failure**: Report which audits are at risk, what readiness gaps remain, what findings are overdue for remediation, and recommended escalation actions. Escalate to General Counsel if certification is at risk.4647## Related Skills4849- [`compliance-framework-implementer`](../compliance-framework-implementer/SKILL.md) -- Framework implementation produces the controls that audits validate.50- [`soc2-programme-manager`](../soc2-programme-manager/SKILL.md) -- SOC 2 is a specific audit programme managed within the broader audit programme.