workpapers-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@workpapers-mcptrace control A3 from risk to test result"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
workpapers-mcp
An MCP server over my itgc-audit-workpapers pack: an IT General Controls audit of my own AWS environment, written up as five markdown workpapers. This server exposes that pack as tools any MCP-capable AI client can call.
Audit workpapers are cross-referenced by design. A risk points to a control, the control points to a test, the test points to a finding. Following those links by hand means flipping between files. With this server a model can trace a control from risk to result in one call, or answer "whats still open?" straight from the files.
Tools
Tool | What it does |
| Full text of workpaper 1 to 5 |
| Findings with rating and status, optional rating filter |
| One control traced end to end: matrix row, test procedure and result, findings that cite the test |
| Findings not remediated, tests without a plain Pass, and unfinished drafting placeholders |
Related MCP server: Security Controls MCP Server
Setup
python3 -m venv .venv
.venv/bin/pip install mcpWire it into Claude Code:
claude mcp add workpapers -- /path/to/workpapers-mcp/.venv/bin/python /path/to/workpapers-mcp/server.pyThe server reads the pack from ~/aiProjects/aminWork/automation-portfolio/itgc-audit-workpapers. Change DATA_DIR at the top of server.py to point it somewhere else.
Demo
What it looks like from Claude Code:
> trace control A3 in the workpapers
⏺ workpapers · control_lookup("A3")
A3 (Domain 1: Access)
Risk: Password-only sign-in is phishable
Control: MFA enforced on every human identity
Where it lives: IAM MFA config
Criteria: CIS 1.10
**T-A3 MFA enforcement.**
ToD/ToE: MFA device listing inspected for all 12 demo users.
Result: Exception, see F-2.
Findings citing T-A3: F-2 Two users without MFA
> anything still open?
⏺ workpapers · open_items()
2 open item(s):
- Finding F-2 Two users without MFA: Open
- Test T-A3: Exception, see F-2.
⏺ One real gap. Two users have no MFA, raised as F-2 and still open.
The T-A3 exception is the same issue seen from the test side.The controls and findings above are demo data. The format is exactly what the server returns.
Design notes
Read-only by construction. Every tool reads markdown files. Nothing writes, deletes or touches the network.
Parses the pack as written. Matrix rows, bold test headings and
## F-N.finding sections are the real structure of the workpapers, so the tools follow the same cross-references a reviewer would.Drafting notes stay private. Square bracket
[REVIEW NOTE ...]placeholders are replaced with a neutral marker before any text leaves the server, andopen_itemscounts them so unfinished work still shows up.
Honest notes
The parsing is tied to this pack's markdown conventions. A workpaper written in a different layout wont parse without changes to the regexes.
The pack is a self-audit of one small personal AWS account. The tools make it easier to navigate. They dont add assurance the workpapers dont already carry.
open_itemstreats any finding whose status doesnt start with "Remediated" as open, so accepted and disclosed limitations show up there on purpose.The test lives in
test_server.pyand runs against a synthetic pack in a temp dir. Run it withpython test_server.pyor pytest.
About
Al Amin Bashir Afara, Dubai · github.com/aminafara123 · linkedin.com/in/aminafara
This server cannot be deployed
Maintenance
Related MCP Connectors
Your audit methodology inside Claude: findings, risks, controls and workpapers in your team format.
Query financial statements, KPIs, ratios, cash forecasts and budgets from your general ledger
Governance maturity assessment, compliance gap analysis, and evidence-linked briefs for AI agents.
AI inventory and EU AI Act compliance. Find AI tools and use cases, check new AI uses before launch.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceProvides search, detail lookup, and gap listing tools for a security control inventory, enabling natural language queries about control status and gaps.-
- AlicenseAqualityCmaintenanceEnables searching and bidirectional mapping of 1,451 security controls across 262 SCF-mapped frameworks, including ISO 27001, NIST CSF, DORA, and many others, through natural language queries.142,162 PyPI9Apache 2.0
- FlicenseNot gradedqualityDmaintenanceEnables authorized compliance verification and security auditing through natural language, bridging AI assistants with industry-standard security tools for enterprise audits.24-
- FlicenseNot gradedqualityCmaintenanceEnables AI assistants to query and manage a GxP computerized system inventory as a knowledge graph, including blast-radius impact analysis, regulatory lineage, validation-gap detection, audit-trail-compliant status change approvals, and periodic review generation.-