compliance
FeaturedUse when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or standing up the cadence that keeps it audit-ready. NOT drafting privacy-policy/ROPA/DPA or ToS text (that is gdpr-privacy, terms-conditions), NOT hardening code (that is secure-coding).
Install
Quality Score: 92/100
Skill Content
Details
- Author
- ericrisco
- Repository
- ericrisco/rsc-harness
- Created
- 3 months ago
- Last Updated
- 2 days ago
- Language
- JavaScript
- License
- MIT
Similar Skills
Semantically similar based on skill content — not just same category
compliance
Creates, maintains and audits COMPLIANCE.md — the project's declared compliance posture (which regimes apply, the self-assessed classification, the obligations that follow, data handling). EU-first (EU AI Act + GDPR as two independent axes). Reads BUSINESS.md's archetype as a TRIGGER for whether the AI Act may apply — it never assigns the legal tier from the archetype alone. Three modes: bootstrap, update, and `audit` (does the diff touch regulated ground — a new personal-data field, a new model/automated decision, a new data source — against the declared posture; read-only). Surfaces provisions & checklists, NEVER a legal verdict. Optionally verifies live via an EU-AI-Act MCP if one is connected; works offline without it. Do NOT use it for status (PROGRESS.md), rules (CLAUDE.md), non-goals (BUSINESS.md) or decision rationale (DECISIONS.md).
compliance
This skill should be used when reviewing code handling PII, payment data, health records, audit logs, data retention, or IaC under GDPR, HIPAA, PCI DSS, SOC 2, ISO 27001, or SOX.
safety-compliance-scoping
Scope which safety and regulatory compliance frameworks plausibly apply to a system — functional safety standards, medical device classification pathways, industrial safety directives — based on its actual use case and failure consequence, before deep technical or product investment. Use early, whenever a system's use case touches health, safety, or regulated industrial contexts, to identify what compliance burden is coming rather than discovering it after the architecture is locked in. This produces a scoping map, not a certification — a qualified regulatory/compliance professional and, where relevant, legal counsel must own the actual compliance path.