Skill 详情

audit-report-writing

Comprehensive audit-report writing, limited to privacy audits.

匹配类型可能匹配已针对 报告撰写 审核
来源mukul975/privacy-data-protection-skills外部来源
报告安装量29仅表示受欢迎程度

使用前先检查

自动化审核只检查相关性,不代表安全审查或推荐。使用前请阅读来源中的说明。

已保存的来源预览

SKILL.md

这段内容是审核时保存的快照。外部来源才是完整且最新的版本。

---
name: audit-report-writing
description: >-
  Guides privacy audit report writing including executive summary drafting,
  findings classification (critical, high, medium, low), evidence referencing,
  root cause analysis documentation, recommendation formulation, management
  response tracking, and report distribution protocols. Covers report structure
  from scope definition through appendices and sign-off. Keywords: audit report,
  findings documentation, executive summary, recommendations, report structure,
  privacy audit deliverables.
license: Apache-2.0
metadata:
  author: mukul975
  version: "1.0"
  domain: privacy
  subdomain: privacy-audit-certification
  tags: "audit-report, findings-documentation, executive-summary, recommendations, report-structure"
---

# Privacy Audit Report Writing

## Overview

Privacy audit report writing is the discipline of translating audit fieldwork into a structured, defensible written deliverable that communicates audit objectives, methodology, findings, and recommendations to stakeholders. A well-crafted audit report serves as the primary vehicle for communicating the state of privacy compliance to governance bodies, management, regulators, and data protection authorities.

Under GDPR Article 39(1)(b), the Data Protection Officer must monitor compliance including audits, meaning audit reports are a key instrument of DPO oversight. ISO 19011:2018 (Guidelines for auditing management systems) Section 6.6 provides the international standard framework for audit report content and distribution.

## Report Structure

### Standard Sections

| Section | Purpose | Typical Length |
|---------|---------|---------------|
| Cover Page | Report identification, classification, distribution list | 1 page |
| Executive Summary | High-level findings, overall opinion, critical issues | 1-2 pages |
| Table of Contents | Navigation aid | 1 page |
| Audit Scope and Objectives | What was audited, boundaries, exclusions | 1-2 pages |
| Methodology | Audit approach, sampling, tools used | 1-2 pages |
| Findings and Observations | Detailed findings with evidence, risk rating, root cause | 5-20 pages |
| Recommendations | Prioritised corrective actions | 2-5 pages |
| Management Response | Auditee agreement/disagreement, action plans, deadlines | 2-5 pages |
| Appendices | Evidence references, sampling details, interview logs | Variable |

## Findings Classification

### Severity Ratings

| Rating | Definition | Response Timeline |
|--------|-----------|-------------------|
| Critical | Material non-compliance creating immediate risk of regulatory enforcement, data breach, or significant harm to data subjects | Immediate remediation; board notification within 24 hours |
| High | Significant control weakness or non-compliance that could lead to a breach or regulatory action if not addressed | Remediation plan within 14 days; completion within 60 days |
| Medium | Control deficiency that does not currently pose immediate risk but could deteriorate | Remediation within 90 days |
| Low | Opportunity for improvement; minor procedural gap | Remediation within 180 days or next audit cycle |
| Observation | Good practice note or suggestion; not a formal finding | No mandatory action |

## Finding Documentation Format

Each finding should include:

| Element | Description |
|---------|-------------|
| Finding ID | Unique identifier (e.g., AUDIT-2026-001) |
| Title | Concise descriptive title |
| Condition | What was observed (the current state) |
| Criteria | What was expected (the standard, policy, or regulation) |
| Cause | Root cause analysis (why the gap exists) |
| Effect | Impact or potential impact of the finding |
| Risk Rating | Critical / High / Medium / Low |
| Recommendation | Specific corrective action |
| Management Response | Auditee's response, action plan, responsible owner, deadline |
| Evidence Reference | Document IDs, screenshots, interview notes |

## Executive Summary Writing

The executive summar
在 GitHub 阅读完整来源 (打开外部页面)
相关上下文

相关工作