uae-grc

Featured

United Arab Emirates Governance, Risk & Compliance advisor — a jurisdiction-first compliance router. In the UAE, WHERE an organization sits determines its law: mainland (Federal PDPL, Decree-Law 45/2021 — executive regulations still pending), DIFC (DP Law No. 5 of 2020 as amended 2025, with a private right of action), ADGM (DP Regulations 2021), CBUAE-licensed financial institutions (consumer-data residency, outsourcing approvals), healthcare (ICT Health Law data localization), and government/CNI (UAE IA Regulation, Cyber Security Council; Dubai ISR, ADHICS). Use for any UAE / Dubai / Abu Dhabi / Emirates compliance question: UAE data protection, DIFC or ADGM privacy, free-zone vs mainland obligations, health-data residency, CBUAE cyber and outsourcing rules, market entry ("expanding to the UAE"), breach notification, gap assessments, and mapping UAE requirements to ISO 27001 / NIST CSF / SOC 2. Trigger for any UAE privacy, cybersecurity, or regulatory question even if no framework is named.

Data & Documents 890 stars 179 forks Updated 5 days ago MIT

Install

View on GitHub

Quality Score: 93/100

Stars 20%
98
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# UAE GRC Advisor > **Last verified:** 2026-08-15 You are a United Arab Emirates governance, risk, and compliance advisor. In the UAE, **jurisdiction is part of the compliance question**: a DIFC fintech, a mainland retailer, an ADGM asset manager, a Dubai hospital, and a federal agency live under materially different regimes. Your first job on any substantive question is **routing** — establish where the organization sits and what it does, then which instruments apply, then advise. Never give obligation detail before the jurisdictional picture is set. ## Step 1 — Intake Gate (always run this first) Establish (ask if not stated; state assumptions if you must proceed): 1. **Jurisdiction** — mainland UAE / DIFC / ADGM / other free zone (incl. Dubai Healthcare City) / multiple 2. **Organization type** — private company / CBUAE-licensed financial institution / DFSA- or FSRA-regulated firm / government or semi-government entity / CNI operator / healthcare provider 3. **Emirate** — Dubai (DESC ISR for government), Abu Dhabi (ADDA standard; ADHICS for DoH-regulated health entities), other 4. **Personal data processed** — UAE residents' data? **health data** (triggers the ICT Health Law regardless of zone)? banking/credit data (sector rules)? 5. **Cloud posture & data locations** — where is data stored/processed/supported from? Consumer financial data? Health data? 6. **Existing certifications** — ISO 27001, SOC 2, etc. (cross-mapping and evidence reuse) ## Step 2 — Jurisdiction...

Details

Author
Sushegaad
Repository
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Created
5 months ago
Last Updated
5 days ago
Language
HTML
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category

Web & Frontend Featured

saudi-arabia-grc

Saudi Arabia Governance, Risk & Compliance advisor — a compliance router that first determines WHICH Saudi regulations apply (NCA ECC-2:2024, Saudi PDPL, NCA Cloud Cybersecurity Controls, SAMA Cyber Security Framework, CST cloud framework, DCC/OTCC/TCC), then guides framework-specific compliance. Use for any Saudi Arabia / KSA compliance question: NCA Essential Cybersecurity Controls, SDAIA and the Personal Data Protection Law (نظام حماية البيانات الشخصية), PDPL breach notification and data transfers, SAMA compliance for banks/insurers/fintechs, cloud data residency in the Kingdom, CST CSP registration, government/CNI cybersecurity obligations, market-entry compliance ("expanding to Saudi Arabia"), gap assessments, and mapping Saudi requirements to ISO 27001 / NIST CSF / SOC 2. Trigger for any KSA, Riyadh, Vision 2030 compliance, NCA, SDAIA, SAMA, or Saudi data protection question even if no framework is named.

890 Updated 5 days ago
Sushegaad
AI & Automation Listed

gcc-market-intelligence

GCC (Saudi Arabia, UAE, Qatar, Bahrain, Kuwait, Oman) market entry intelligence for non-GCC founders of operating or scaling B2B / B2G startups. Use this skill whenever the user mentions Saudi Arabia, KSA, UAE, Dubai, Abu Dhabi, Sharjah, Doha, Qatar, Bahrain, Manama, Kuwait, Oman, Muscat, MENA, GCC, Gulf, Khaleej, Vision 2030, NEOM, PIF, ADIA, Mubadala, RHQ, Saudization, Emiratisation, Nitaqat, Etimad, LEAP, GITEX, FII, Hub71, Garage, in5, Sheraa, Tamkeen, Madinah Tech Cultivator, or any ruling/merchant family (Al Saud, Al Nahyan, Al Maktoum, Al Qasimi, Al Nuaimi, Al Mualla, Al Sharqi, Al Thani, Al Sabah, Al Khalifa, Al Said, Olayan, Al Rajhi, Al Muhaidib, Al Futtaim, Majid Al Futtaim, Al Ghurair, Al Habtoor, Al Tayer, IHC, Kingdom Holding, etc.). Use this skill EVEN IF the user does not explicitly say "Gulf" or "GCC" but mentions any of these countries / cities / entities in a market-entry, sales, partnership, fundraising, or competitive-intelligence context. Also use when the user asks about market sizing,

0 Updated yesterday
Tandiestablished875
AI & Automation Featured

eu-ai-act

EU AI Act (Regulation (EU) 2024/1689) compliance advisor — risk classification across all four tiers, all 9 prohibited practices (Art. 5, including the nudification/CSAM prohibition from Dec 2, 2026), all 8 Annex III high-risk use case areas, provider and deployer obligations (Arts. 9–17, 26), GPAI model obligations including the July 2025 Code of Practice (Arts. 51–55), conformity assessment and CE marking (Arts. 43–48), EU AI database registration, Art. 50 transparency (chatbots, synthetic media, AI-generated content), governance (AI Office, AI Board), penalties (Art. 99), confirmed phase-in timeline (Digital Omnibus, Reg. (EU) 2026/1744, in force July 27, 2026: Annex III deferred to Dec 2, 2027; Annex I to Aug 2, 2028), and cross-framework mapping to ISO 42001, NIST AI RMF, and GDPR. Use for any EU AI regulation, AI system classification, or AI compliance question. Current as of August 2026. GPAI enforcement powers active since August 2, 2026.

890 Updated 5 days ago
Sushegaad