Skill 詳細

audit-report-writing

Comprehensive audit-report writing, limited to privacy audits.

一致度一致の可能性レポート作成 向けにレビュー済み
出典mukul975/privacy-data-protection-skills外部ソース
報告インストール数29人気度の参考値

使用前に確認

自動レビューは関連性のみを確認し、安全性や推奨を保証しません。使用前に出典の説明を読んでください。

保存された出典プレビュー

SKILL.md

これはレビュー時に保存された抜粋です。完全で最新の内容は外部ソースを確認してください。

---
name: audit-report-writing
description: >-
  Guides privacy audit report writing including executive summary drafting,
  findings classification (critical, high, medium, low), evidence referencing,
  root cause analysis documentation, recommendation formulation, management
  response tracking, and report distribution protocols. Covers report structure
  from scope definition through appendices and sign-off. Keywords: audit report,
  findings documentation, executive summary, recommendations, report structure,
  privacy audit deliverables.
license: Apache-2.0
metadata:
  author: mukul975
  version: "1.0"
  domain: privacy
  subdomain: privacy-audit-certification
  tags: "audit-report, findings-documentation, executive-summary, recommendations, report-structure"
---

# Privacy Audit Report Writing

## Overview

Privacy audit report writing is the discipline of translating audit fieldwork into a structured, defensible written deliverable that communicates audit objectives, methodology, findings, and recommendations to stakeholders. A well-crafted audit report serves as the primary vehicle for communicating the state of privacy compliance to governance bodies, management, regulators, and data protection authorities.

Under GDPR Article 39(1)(b), the Data Protection Officer must monitor compliance including audits, meaning audit reports are a key instrument of DPO oversight. ISO 19011:2018 (Guidelines for auditing management systems) Section 6.6 provides the international standard framework for audit report content and distribution.

## Report Structure

### Standard Sections

| Section | Purpose | Typical Length |
|---------|---------|---------------|
| Cover Page | Report identification, classification, distribution list | 1 page |
| Executive Summary | High-level findings, overall opinion, critical issues | 1-2 pages |
| Table of Contents | Navigation aid | 1 page |
| Audit Scope and Objectives | What was audited, boundaries, exclusions | 1-2 pages |
| Methodology | Audit approach, sampling, tools used | 1-2 pages |
| Findings and Observations | Detailed findings with evidence, risk rating, root cause | 5-20 pages |
| Recommendations | Prioritised corrective actions | 2-5 pages |
| Management Response | Auditee agreement/disagreement, action plans, deadlines | 2-5 pages |
| Appendices | Evidence references, sampling details, interview logs | Variable |

## Findings Classification

### Severity Ratings

| Rating | Definition | Response Timeline |
|--------|-----------|-------------------|
| Critical | Material non-compliance creating immediate risk of regulatory enforcement, data breach, or significant harm to data subjects | Immediate remediation; board notification within 24 hours |
| High | Significant control weakness or non-compliance that could lead to a breach or regulatory action if not addressed | Remediation plan within 14 days; completion within 60 days |
| Medium | Control deficiency that does not currently pose immediate risk but could deteriorate | Remediation within 90 days |
| Low | Opportunity for improvement; minor procedural gap | Remediation within 180 days or next audit cycle |
| Observation | Good practice note or suggestion; not a formal finding | No mandatory action |

## Finding Documentation Format

Each finding should include:

| Element | Description |
|---------|-------------|
| Finding ID | Unique identifier (e.g., AUDIT-2026-001) |
| Title | Concise descriptive title |
| Condition | What was observed (the current state) |
| Criteria | What was expected (the standard, policy, or regulation) |
| Cause | Root cause analysis (why the gap exists) |
| Effect | Impact or potential impact of the finding |
| Risk Rating | Critical / High / Medium / Low |
| Recommendation | Specific corrective action |
| Management Response | Auditee's response, action plan, responsible owner, deadline |
| Evidence Reference | Document IDs, screenshots, interview notes |

## Executive Summary Writing

The executive summar
GitHub で全文を読む (外部ページ)
関連情報

関連する仕事