compliance-tracking
$
npx mdskill add anthropics/knowledge-work-plugins/compliance-trackingTracks compliance requirements and prepares for audits when triggered by regulatory keywords or compliance activities.
- Helps users manage compliance frameworks like SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS.
- Integrates with control inventory, audit calendar, evidence management, and gap analysis tools.
- Decides based on user input keywords such as compliance, audit prep, or specific regulatory terms.
- Presents results through structured outputs like tables, timelines, and prioritized remediation plans.
SKILL.md
.github/skills/compliance-trackingView on GitHub ↗
--- name: compliance-tracking description: Track compliance requirements and audit readiness. Trigger with "compliance", "audit prep", "SOC 2", "ISO 27001", "GDPR", "regulatory requirement", or when the user needs help tracking, preparing for, or documenting compliance activities. --- # Compliance Tracking Help track compliance requirements, prepare for audits, and maintain regulatory readiness. ## Common Frameworks | Framework | Focus | Key Requirements | |-----------|-------|-----------------| | SOC 2 | Service organizations | Security, availability, processing integrity, confidentiality, privacy | | ISO 27001 | Information security | Risk assessment, security controls, continuous improvement | | GDPR | Data privacy (EU) | Consent, data rights, breach notification, DPO | | HIPAA | Healthcare data (US) | PHI protection, access controls, audit trails | | PCI DSS | Payment card data | Encryption, access control, vulnerability management | ## Compliance Tracking Components ### Control Inventory - Map controls to framework requirements - Document control owners and evidence - Track control effectiveness ### Audit Calendar - Upcoming audit dates and deadlines - Evidence collection timelines - Remediation deadlines ### Evidence Management - What evidence is needed for each control - Where evidence is stored - When evidence was last collected ### Gap Analysis - Requirements vs. current state - Prioritized remediation plan - Timeline to compliance ## Output Produce compliance status dashboards, gap analyses, audit prep checklists, and evidence collection plans.
More from anthropics/knowledge-work-plugins
- accessibility-reviewRun a WCAG 2.1 AA accessibility audit on a design or page. Trigger with "audit accessibility", "check a11y", "is this accessible?", or when reviewing a design for color contrast, keyboard navigation, touch target size, or screen reader behavior before handoff.
- account-research"Research a company using Common Room data. Triggers on 'research [company]', 'tell me about [domain]', 'pull up signals for [account]', 'what's going on with [company]', or any account-level question."
- analyzeAnswer data questions -- from quick lookups to full analyses. Use when looking up a single metric, investigating what's driving a trend or drop, comparing segments over time, or preparing a formal data report for stakeholders.
- architectureCreate or evaluate an architecture decision record (ADR). Use when choosing between technologies (e.g., Kafka vs SQS), documenting a design decision with trade-offs and consequences, reviewing a system design proposal, or designing a new component from requirements and constraints.
- audit-supportSupport SOX 404 compliance with control testing methodology, sample selection, and documentation standards. Use when generating testing workpapers, selecting audit samples, classifying control deficiencies, or preparing for internal or external audits.
- brand-reviewReview content against your brand voice, style guide, and messaging pillars, flagging deviations by severity with specific before/after fixes. Use when checking a draft before it ships, when auditing copy for voice consistency and terminology, or when screening for unsubstantiated claims, missing disclaimers, and other legal flags.
- brand-voice-enforcement>
- briefGenerate contextual briefings for legal work — daily summary, topic research, or incident response. Use when starting your day and need a scan of legal-relevant items across email, calendar, and contracts, when researching a specific legal question across internal sources, or when a developing situation (data breach, litigation threat, regulatory inquiry) needs rapid context.
- build-dashboardBuild an interactive HTML dashboard with charts, filters, and tables. Use when creating an executive overview with KPI cards, turning query results into a shareable self-contained report, building a team monitoring snapshot, or needing multiple charts with filters in one browser-openable file.
- build-zoom-botBuild a Zoom meeting bot, recorder, or real-time media workflow. Use when joining meetings programmatically, processing live media or transcripts, or combining Meeting SDK, RTMS, and backend services.