compliance-ops-getting-started

$npx mdskill add Significant-Gravitas/skills-catalog/compliance-ops-getting-started

Use this before drafting a questionnaire, a data map, or a request reply.

SKILL.md

.github/skills/compliance-ops-getting-startedView on GitHub ↗
---
name: "compliance-ops-getting-started"
description: "Set up compliance work from policies, system inventory, audit reports, approved answers, and counsel contacts."
triggers: ["compliance setup", "privacy setup", "start compliance", "security review process", "GDPR setup"]
version: "1"
---

# Compliance ops getting started

Use this before drafting a questionnaire, a data map, or a request reply.

## Build the evidence library

Ask for the written policies, the system inventory, audit or penetration test
reports, certificates with their dates and scope, signed DPAs, the
subprocessor list, and past questionnaire answers that someone approved. For
each item record the title, version, owner, date, and where it lives.

Mark items that are drafts, out of date, or unsigned. An audit in progress is
not a certificate; record it as in progress.

## Set the handoff rules

Agree who owns each area: security controls, infrastructure, HR, contracts,
and privacy requests. Name the counsel contact and the security lead. Agree
which questions always go to counsel (liability, legal basis, breach
reporting, regulator contact) and who approves and submits each answer.

## Return the setup brief

Give the user:

1. The evidence library, with dates and owners.
2. Items that are missing, stale, or unsigned.
3. Owners for each area, and the counsel and security contacts.
4. Open deadlines: questionnaires, DPAs, and data subject requests.
5. The first three pieces of work, with reasons.

Never claim a certification or control that the evidence does not show, and do
not state that the company is compliant with a law. This is not legal advice.
Draft for owners and counsel; never sign, submit, or send anything.

More from Significant-Gravitas/skills-catalog

SkillDescription
account-health-and-qbrsUse when a support account wobbles or a quarterly business review looms: read the health signals, run the success plan, and prep the review from evidence.
accounts-receivable-follow-upReview open receivables and draft factual, staged payment follow-ups without inventing status or contacting a customer.
ad-copy-variantsWrite ad variants that each test one idea, within platform limits and supported claims.
alex-getting-startedUse on the first conversation with Alex, or whenever their memory has no product preferences yet: learn what the user is building and who for, where specs, roadmap and numbers live, who decides dates and scope, and get them to a first real product deliverable.
alliance-co-commercializationUse when a strategic alliance needs joint selling governance: operating model, joint targeting, steering prep, and milestone accountability.
anika-getting-startedUse on the first conversation with Anika, or whenever their memory has no partnership preferences yet: learn which partners and alliances the user owns, what motion they run, and get one real partner read on screen in the same session.
assure-partner-led-deliveryUse when partners deliver client work in your name: own the in-flight book, run the weekly delivery review, and rescue engagements before clients feel it.
automate-finance-reportingUse to connect a number source, map an export into the finance ledger, or QA a sheet: the column mapping, the dedupe key, the load summary, and the checks that must pass before a read ships.
billing-refunds-and-exceptionsUse when money is on the table: verify the charge, check the policy, and stage a refund or exception draft that stops at the owner's yes.
board-and-investor-metrics-briefPrepare a concise board or investor metrics brief with definitions, sources, comparisons, drivers, risks, and decisions needed.