compliance

Featured

Use when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or standing up the cadence that keeps it audit-ready. NOT drafting privacy-policy/ROPA/DPA or ToS text (that is gdpr-privacy, terms-conditions), NOT hardening code (that is secure-coding).

AI & Automation 116 stars 9 forks Updated 2 days ago MIT

Install

View on GitHub

Quality Score: 92/100

Stars 20%
69
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Compliance — scope the frameworks, build the register, run the rhythm You turn a vague "we need to be compliant" into artifacts that survive an audit: a scoped framework list with current deadlines, a **control register** (one row per control, tagged to every framework it satisfies, each with an owner and an evidence source), a **cadence calendar** of the recurring work that keeps the program true between audits instead of scrambling once a year, and an evidence-source catalog. Your job is **scoping and orchestration, not legal opinion**. You map the business to the frameworks, build the register, assign owners and cadences, and stand up the rhythm. You do not give legal advice; flag where a licensed specialist or auditor must sign off. **Route out** — these are owned by siblings, not by you. You *reference* the resulting documents as evidence sources in the register; you do not write them here. - Privacy notice, ROPA, DSAR flow, consent banner → `../gdpr-privacy/SKILL.md`. - Terms of Service, EULA, acceptable-use → `../terms-conditions/SKILL.md`. - Internal retention/classification policy *text* → `../data-policy/SKILL.md`. - Commercial contract / MSA / DPA clause drafting → `../contracts/SKILL.md`. - Hardening the code (authn, secrets, injection, headers) → `../secure-coding/SKILL.md`. ## Step 1 — Scope to the frameworks that actually bind Do not copy a framework because a competitor has it. Map business attributes to obligations. Ask the operator the attribute qu...

Details

Author
ericrisco
Repository
ericrisco/rsc-harness
Created
3 months ago
Last Updated
2 days ago
Language
JavaScript
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Listed

compliance

Creates, maintains and audits COMPLIANCE.md — the project's declared compliance posture (which regimes apply, the self-assessed classification, the obligations that follow, data handling). EU-first (EU AI Act + GDPR as two independent axes). Reads BUSINESS.md's archetype as a TRIGGER for whether the AI Act may apply — it never assigns the legal tier from the archetype alone. Three modes: bootstrap, update, and `audit` (does the diff touch regulated ground — a new personal-data field, a new model/automated decision, a new data source — against the declared posture; read-only). Surfaces provisions & checklists, NEVER a legal verdict. Optionally verifies live via an EU-AI-Act MCP if one is connected; works offline without it. Do NOT use it for status (PROGRESS.md), rules (CLAUDE.md), non-goals (BUSINESS.md) or decision rationale (DECISIONS.md).

0 Updated today
radozaprazny
Code & Development Listed

compliance

This skill should be used when reviewing code handling PII, payment data, health records, audit logs, data retention, or IaC under GDPR, HIPAA, PCI DSS, SOC 2, ISO 27001, or SOX.

19 Updated today
dean0x
AI & Automation Listed

safety-compliance-scoping

Scope which safety and regulatory compliance frameworks plausibly apply to a system — functional safety standards, medical device classification pathways, industrial safety directives — based on its actual use case and failure consequence, before deep technical or product investment. Use early, whenever a system's use case touches health, safety, or regulated industrial contexts, to identify what compliance burden is coming rather than discovering it after the architecture is locked in. This produces a scoping map, not a certification — a qualified regulatory/compliance professional and, where relevant, legal counsel must own the actual compliance path.

1 Updated today
hemapriyan-rk