---
name: "compliance-ops-getting-started"
description: "Set up compliance work from policies, system inventory, audit reports, approved answers, and counsel contacts."
triggers: ["compliance setup", "privacy setup", "start compliance", "security review process", "GDPR setup"]
version: "1"
---
# Compliance ops getting started
Use this before drafting a questionnaire, a data map, or a request reply.
## Build the evidence library
Ask for the written policies, the system inventory, audit or penetration test
reports, certificates with their dates and scope, signed DPAs, the
subprocessor list, and past questionnaire answers that someone approved. For
each item record the title, version, owner, date, and where it lives.
Mark items that are drafts, out of date, or unsigned. An audit in progress is
not a certificate; record it as in progress.
## Set the handoff rules
Agree who owns each area: security controls, infrastructure, HR, contracts,
and privacy requests. Name the counsel contact and the security lead. Agree
which questions always go to counsel (liability, legal basis, breach
reporting, regulator contact) and who approves and submits each answer.
## Return the setup brief
Give the user:
1. The evidence library, with dates and owners.
2. Items that are missing, stale, or unsigned.
3. Owners for each area, and the counsel and security contacts.
4. Open deadlines: questionnaires, DPAs, and data subject requests.
5. The first three pieces of work, with reasons.
Never claim a certification or control that the evidence does not show, and do
not state that the company is compliant with a law. This is not legal advice.
Draft for owners and counsel; never sign, submit, or send anything.