An ISMS audit can look complete while its conclusion rests on a convenient screenshot, an interview nobody corroborated, or a severity label borrowed from another program. This skill keeps the audit tied to the actual mandate, controlled criteria, sampled population, and evidence available.
It builds the scope and criteria register, maps risk-based coverage, separates control design from implementation and operation, preserves contradictory evidence, and drafts findings that trace from requirement to condition to consequence. Corrective actions stay open until implementation, retest, effectiveness, residual issues, and approval support closure.
Use it for ISO/IEC 27001 internal audits, supplier ISMS audits, certification-readiness work, control sampling, finding review, or corrective-action follow-up. It does not reproduce licensed standards, conduct an external certification audit, or promise certification. A bundled read-only checker validates the structure and cross-references of a JSON audit record without deciding conformity.