agentsclimarketplace

Internal privacy audit

Skill onfire7777/universal-ai-skills-library/skills/internal-privacy-audit

Router-first AI skill system for Codex, Claude, Cursor, Hermes, Paperclip, OpenCode, and local AI stacks: search, preflight-route, and load 1,812 skills on demand without duplicating the corpus.

Install
npx -y skills add onfire7777/universal-ai-skills-library --skill internal-privacy-audit

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 13 stars13 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Guides internal privacy audit program design and execution including risk-based audit planning, scope definition, fieldwork procedures, finding classification, evidence gathering, remediation tracking, and management reporting. Covers audit universe definition, annual audit plan, working papers, and closure verification. Keywords: internal audit, privacy audit, fieldwork, remediation, findings, audit plan.

The file declares its own license as Apache-2.0. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

18.7 KB, ~4.0k tokens by cl100k_base, as published. Nobody here has run it

Internal Privacy Audit Program

Overview

An internal privacy audit program provides systematic, independent assurance that an organization's privacy practices conform to applicable data protection regulations, internal policies, contractual obligations, and recognized frameworks. Unlike external audits (SOC 2, ISO 27701 certification), internal privacy audits are conducted by or on behalf of the organization itself, giving management direct visibility into compliance gaps before they become regulatory findings or breaches.

The internal privacy audit function operates under the IIA (Institute of Internal Auditors) International Standards for the Professional Practice of Internal Auditing and adapts these standards to the privacy domain. At Sentinel Compliance Group, the internal privacy audit program reports to the Audit Committee of the Board of Directors, maintaining independence from the privacy operations function it audits.

Audit Universe Definition

The privacy audit universe represents the complete set of auditable entities, processes, and systems relevant to privacy compliance. It forms the basis for risk-based audit planning.

Privacy Audit Universe Categories

CategoryAuditable AreasExample Entities
Regulatory ComplianceGDPR, CCPA/CPRA, LGPD, PIPA, sector-specific lawsEU processing operations, California consumer data handling, Brazilian customer data
Data LifecycleCollection, processing, storage, sharing, retention, deletionWeb forms, CRM system, data warehouse, third-party APIs, backup systems
Data Subject RightsAccess, rectification, erasure, portability, restriction, objectionDSAR intake process, identity verification, response workflow, automated systems
Third-Party ManagementProcessors, sub-processors, joint controllers, data sharingCloud hosting, analytics vendors, marketing platforms, payment processors
Privacy GovernancePolicies, training, DPO function, privacy committee, DPIA processPrivacy policy management, training program, DPO independence, DPIA register
Technical ControlsEncryption, access controls, pseudonymization, logging, deletionDatabase encryption, IAM configuration, log management, automated purge jobs
Breach ManagementDetection, assessment, notification, documentation, remediationSIEM configuration, breach assessment process, DPA notification, root cause analysis
Cross-Border TransfersTransfer mechanisms, TIAs, supplementary measuresSCCs, BCRs, adequacy decisions, data localization controls
Consent ManagementCollection, recording, withdrawal, preference managementConsent platforms, cookie banners, preference centers, consent databases
Records of ProcessingRoPA completeness, accuracy, maintenanceController register, processor register, update workflow

Risk-Based Prioritization

Each auditable area is scored on a risk matrix:

Risk FactorWeightScoring (1-5)
Regulatory exposure25%1 = No regulation, 5 = Multiple strict regulations with active enforcement
Volume of personal data20%1 = Minimal PII, 5 = Large-scale special category data
Prior audit findings15%1 = No findings, 5 = Unresolved critical findings
Organizational change15%1 = Stable, 5 = Major system/process changes
Third-party dependency10%1 = No third parties, 5 = Critical third-party processing
Complaint/incident history10%1 = No incidents, 5 = Multiple privacy incidents
Time since last audit5%1 = Audited this quarter, 5 = Never audited or >2 years

Risk Score Calculation: Weighted sum of all factors (maximum 5.0)

Risk ScoreAudit Frequency
4.0 — 5.0Every 6 months
3.0 — 3.9Annual
2.0 — 2.9Every 18 months
1.0 — 1.9Every 24 months or as resources permit

Annual Audit Plan

Plan Development Process

  1. Update Audit Universe (Q4 of preceding year): Review the audit universe for new systems, regulations, processing activities, and organizational changes
  2. Conduct Risk Assessment (Q4): Score each auditable area using the risk matrix above
  3. Allocate Resources (Q4): Determine available audit hours based on team size and skill sets
  4. Draft Annual Plan (Q4): Schedule audits by quarter, balancing risk priority with resource availability and organizational calendar constraints
  5. Management Approval (Q4): Present the annual audit plan to the Audit Committee for approval
  6. Quarterly Review (each quarter): Adjust the plan based on emerging risks, regulatory changes, or management requests

Annual Plan Template

Sentinel Compliance Group — Privacy Audit Annual Plan 2025

Approved By: Audit Committee, December 15, 2024
Plan Owner: Chief Audit Executive

Q1 2025:
  - DSAR Response Process (Risk Score: 4.3, Last Audit: Jun 2024)
  - Cookie Consent Management (Risk Score: 3.8, Last Audit: Mar 2024)

Q2 2025:
  - Third-Party Processor Management (Risk Score: 4.5, Last Audit: Dec 2023)
  - Cross-Border Data Transfers (Risk Score: 4.1, Last Audit: Sep 2024)

Q3 2025:
  - Data Retention and Deletion (Risk Score: 3.9, Last Audit: Jun 2024)
  - Privacy Training Effectiveness (Risk Score: 3.2, Last Audit: Dec 2024)

Q4 2025:
  - Breach Notification Process (Risk Score: 4.0, Last Audit: Mar 2024)
  - Records of Processing Activities (Risk Score: 3.5, Last Audit: Sep 2024)

Reserve/Contingency (50 hours):
  - Ad hoc investigations, management requests, regulatory-triggered audits

Audit Execution Phases

Phase 1: Planning and Scoping (1-2 Weeks)

1.1 Audit Charter Confirmation

Confirm that the internal audit charter authorizes privacy audits and defines:

  • Audit authority and independence
  • Access to records, personnel, and systems
  • Reporting relationships
  • Confidentiality obligations of audit staff

1.2 Preliminary Research

  • Review applicable regulations and recent enforcement actions
  • Review prior audit reports and outstanding findings
  • Review recent privacy incidents, complaints, and DSAR metrics
  • Review organizational changes affecting the audit scope
  • Review regulatory guidance and supervisory authority publications

1.3 Scope Definition

Document the audit scope including:

Scope ElementDescription
ObjectiveWhat the audit intends to evaluate (e.g., adequacy and effectiveness of DSAR response controls)
PeriodThe timeframe under examination (e.g., January 1 — June 30, 2025)
EntitiesOrganizational units in scope
SystemsIT systems and platforms in scope
RegulationsApplicable legal requirements
StandardsApplicable internal policies and external frameworks
ExclusionsExplicitly out-of-scope areas with justification

1.4 Audit Program Development

Create the detailed audit program (test procedures) for each control objective:

Control Objective: DSARs are processed within regulatory timeframes
  Test 1: Obtain DSAR tracking log for the audit period
  Test 2: Select sample of [n] DSARs per sampling methodology
  Test 3: For each sampled DSAR, verify:
    a. Identity verification was completed before disclosure
    b. Response was provided within 30 days (GDPR) or 45 days (CCPA)
    c. Response contained all required information per Art. 15
    d. Extension, if used, was communicated within initial deadline
    e. Denial, if applicable, was justified and communicated with appeal rights
  Test 4: Review DSAR metrics for trend analysis
  Test 5: Interview DSAR coordinators on process adherence

1.5 Engagement Letter

Issue the engagement letter to the audit client (privacy operations team) containing:

  • Audit objective and scope
  • Audit period
  • Expected fieldwork dates
  • Information and access requirements
  • Key contacts
  • Preliminary meeting schedule

Phase 2: Fieldwork (2-4 Weeks)

2.1 Opening Meeting

Conduct an opening meeting with the audit client to:

  • Confirm scope and timing
  • Identify key contacts for each area
  • Discuss logistics (room access, system access, document sharing)
  • Address any concerns or constraints

2.2 Evidence Gathering Techniques

TechniqueApplicationExample
Document ReviewPolicies, procedures, records, reportsReview privacy policy against GDPR Art. 13-14 requirements
InterviewProcess understanding, control awarenessInterview DPO on DPIA review process
ObservationProcess walkthrough, system demonstrationObserve DSAR fulfillment from intake to response
Data AnalysisPopulation analysis, trend identification, anomaly detectionAnalyze DSAR response times across the full population
Technical TestingSystem configuration verificationVerify encryption-at-rest configuration on database
SamplingRepresentative testing of transactionsSelect 30 DSARs from population of 450 for detailed testing
ReperformanceIndependent control executionSubmit test DSAR and verify correct handling

2.3 Sampling Methodology

Internal privacy audit sampling follows IIA Practice Guide "Audit Sampling":

Attribute Sampling (for compliance testing):

Population SizeExpected Error Rate95% Confidence Sample
50-1000% expected30
101-5000% expected40
501-10000% expected50
1000+0% expected60
Any1-5% expectedAdd 10-20 to above

Judgmental Sampling (risk-focused selection):

  • High-value transactions (DSARs involving sensitive data)
  • Edge cases (DSARs with extensions, partial denials, cross-border elements)
  • Time-based distribution (ensure coverage across the entire audit period)
  • New process implementation (overweight periods after process changes)

2.4 Working Paper Standards

Every audit test must be documented in working papers containing:

Working Paper ElementDescription
Reference NumberUnique identifier linked to the audit program test step
ObjectiveWhat the test is designed to evaluate
ProcedureDetailed steps performed
PopulationDescription and size of the population tested
SampleSize and selection methodology
ResultsFactual findings for each sample item
ConclusionPass/Fail determination with reasoning
EvidenceAttached or cross-referenced supporting documentation
PreparerAuditor name and date
ReviewerReviewer name and date

Phase 3: Finding Classification and Reporting (1-2 Weeks)

3.1 Finding Classification

Each finding is classified by severity:

SeverityCriteriaResponse Time
CriticalSystemic non-compliance with regulation; imminent risk of enforcement action, significant data breach, or harm to data subjects; complete control failureImmediate: interim remediation within 5 business days; full remediation within 30 days
HighMaterial non-compliance; control design deficiency or widespread operating failure; significant gap between policy and practiceRemediation plan within 10 business days; full remediation within 60 days
MediumIsolated non-compliance; control operating inconsistently; documentation gaps that could lead to material issuesRemediation within 90 days
LowMinor documentation gaps; process improvement opportunities; control enhancements that would strengthen compliance postureRemediation within 180 days
AdvisoryBest practice recommendations; emerging risk observations; no current non-complianceNo required response; tracked for information

3.2 Finding Structure

Each finding is documented using the Condition-Criteria-Cause-Consequence-Recommendation format:

Finding ID: PA-2025-Q2-003
Title: Incomplete identity verification for DSAR fulfillment
Severity: High
Status: Open

Condition (What did we find?):
  In 6 of 30 sampled DSARs (20%), the identity verification step was not
  completed or documented prior to disclosing personal data to the requestor.
  Affected requests: DSAR-2025-0147, DSAR-2025-0203, DSAR-2025-0289,
  DSAR-2025-0312, DSAR-2025-0378, DSAR-2025-0401.

Criteria (What should be happening?):
  GDPR Art. 12(6) requires controllers to verify the identity of the data
  subject making the request, particularly where the controller has reasonable
  doubts. Sentinel Compliance Group Privacy Procedure PR-DSAR-001 Section 4.2
  requires two-factor identity verification for all DSARs before any personal
  data is disclosed.

Cause (Why did it happen?):
  The DSAR workflow system does not enforce a mandatory verification step before
  allowing the coordinator to mark the request as "in progress." Three of the
  six cases involved requests received via email rather than the self-service
  portal, where the verification workflow is not automated.

Consequence (What is the risk?):
  Without proper identity verification, personal data may be disclosed to
  unauthorized individuals, constituting a personal data breach under Art. 4(12)
  GDPR. This could result in supervisory authority enforcement action, reputational
  harm, and direct harm to data subjects. The ICO fined a UK company GBP 175,000
  in 2023 for disclosing personal data in response to a fraudulent DSAR.

Recommendation:
  1. Implement a mandatory verification gate in the DSAR workflow system that
     blocks progression until verification is completed and documented.
  2. Extend automated verification to email-originated DSARs by redirecting
     requestors to the self-service portal.
  3. Retrain DSAR coordinators on verification requirements.

Management Response: [To be completed by management]
Remediation Owner: [To be assigned]
Target Date: [To be set]

3.3 Audit Report Structure

INTERNAL PRIVACY AUDIT REPORT
Report Number: PA-2025-Q2
Classification: Confidential

1. Executive Summary
   - Audit objective and scope
   - Overall rating (Satisfactory / Needs Improvement / Unsatisfactory)
   - Summary of findings by severity
   - Key themes and systemic issues

2. Audit Scope and Approach
   - Detailed scope description
   - Regulations and standards tested against
   - Methodology (sampling, testing approach)
   - Period covered
   - Limitations and constraints

3. Findings and Recommendations
   - Critical findings (if any)
   - High findings
   - Medium findings
   - Low findings
   - Advisory observations

4. Management Action Plans
   - Agreed remediation actions per finding
   - Responsible owners
   - Target completion dates

5. Prior Audit Follow-Up
   - Status of findings from prior audits
   - Closed findings with verification evidence
   - Overdue findings with escalation status

6. Appendices
   - Detailed test results
   - Population and sample details
   - Documents reviewed
   - Personnel interviewed

3.4 Overall Audit Rating

RatingCriteria
SatisfactoryNo critical or high findings; medium and low findings do not indicate systemic issues; controls are generally effective
Needs ImprovementOne or more high findings OR multiple medium findings indicating a pattern; controls are partially effective but require strengthening
UnsatisfactoryOne or more critical findings OR multiple high findings; fundamental control failures exist; immediate management attention required

Phase 4: Remediation Tracking (Ongoing)

4.1 Remediation Lifecycle

Finding Issued → Management Response (10 business days) → Remediation In Progress
→ Owner Reports Completion → Audit Verification Testing → Finding Closed OR
→ Reopened with Revised Plan

4.2 Tracking Dashboard

MetricMeasurement
Open Findings by SeverityCount of open findings per critical/high/medium/low
Overdue FindingsCount and percentage of findings past target date
Average Time to RemediateMean days from finding issuance to verified closure
Remediation EffectivenessPercentage of findings closed on first attempt (not reopened)
Recurrence RatePercentage of findings that reappear in subsequent audits

4.3 Escalation Protocol

ConditionEscalation Level
Critical finding not addressed within 5 business daysChief Privacy Officer and CISO
High finding overdue by 30+ daysChief Audit Executive to Audit Committee
Medium finding overdue by 60+ daysChief Audit Executive to management
Pattern of repeated findings in same areaChief Audit Executive to Audit Committee
Management refuses to remediateChief Audit Executive to Audit Committee and Board

Phase 5: Management Reporting (Quarterly)

5.1 Quarterly Privacy Audit Report to Audit Committee

  • Summary of audits completed in the quarter
  • Summary of findings by severity and theme
  • Remediation progress dashboard
  • Emerging privacy risks identified
  • Annual audit plan status and any proposed adjustments
  • Resource utilization and any capacity constraints

5.2 Annual Privacy Audit Summary

  • All audits completed during the year
  • Trend analysis of findings across the year
  • Assessment of the organization's overall privacy posture
  • Comparison to prior year
  • Recommendations for the following year's audit plan
  • Lessons learned and methodology improvements

Sentinel Compliance Group Internal Privacy Audit Program

Sentinel Compliance Group operates an internal privacy audit program with the following characteristics:

  • Team: Two dedicated privacy auditors plus one co-sourced external privacy audit specialist
  • Annual Audit Hours: 1,200 hours allocated to privacy audits
  • Audits Per Year: 8-10 privacy audits plus continuous monitoring activities
  • Reporting Line: Chief Audit Executive reports to the Audit Committee; privacy audit results shared with the DPO
  • Tools: AuditBoard for working papers and finding management; ServiceNow for remediation tracking
  • 2024 Results: 9 audits completed, 47 findings issued (2 critical, 8 high, 22 medium, 15 low), 89% remediation rate within target dates, overall privacy posture rated "Needs Improvement" trending toward "Satisfactory"

What ships with it: 4 files

17.5 KB alongside SKILL.md, 1 of them executable

assets/

references/

scripts/

Keep looking

Skills are one crate of 327,069. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.