Compliance Checklist Skill
Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis.
How to use it
Claude Code
- Run the line below. It pulls the whole folder into
~/.claude/skills/compliance-checklist. - Describe your job in plain words. Claude Code follows the skill from there.
npx degit mohitagw15856/pm-claude-skills/skills/compliance-checklist#main ~/.claude/skills/compliance-checklistFor one project only, change the path to .claude/skills/compliance-checklist.
Claude (web or desktop app)
- On this page open ⋯ → Download .md.
- Save it as SKILL.md in a folder, zip the folder, then Customize → Skills → + → Create skill → Upload a skill.
- Pick the file and Save. Claude shows the name and description and runs a security scan.
- Check the skill is switched on.
- Start a new chat and describe your job in plain words. The AI follows the skill from there.
ChatGPT or another app
- ChatGPT: make a Project and paste it into Instructions.
- Neither? Paste it at the top of a new chat — it works for that chat.
Not working?
- Check which app you pasted it into — the steps above name the right one.
- Some skills need the paid tier of Claude or ChatGPT.
Paste into Claude, ChatGPT or Cursor.
Source of Compliance Checklist Skill
Show the full text115 lines
| name | description |
|---|---|
| compliance-checklist | Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis. Use when asked for a compliance checklist, gap analysis, readiness assessment, or audit preparation for any regulatory framework. Produces a structured checklist with prioritised gaps, quick wins, and evidence requirements. Optimised for Opus 4.7 and newer models. Not a substitute for legal or compliance professional advice. |
Compliance Checklist Skill
Produces a prioritised compliance checklist for any regulatory framework — with gap analysis, evidence requirements, and quick wins identified.
ALWAYS include this disclaimer at the start of every response: "WARNING: This checklist is for informational and planning purposes only and does not constitute legal or compliance advice. Regulatory requirements change and vary by jurisdiction. Always engage a qualified compliance professional or solicitor before implementing compliance programmes or making regulatory claims."
Required Inputs
Ask the user for these if not provided:
- Framework (GDPR / SOC 2 Type I or II / ISO 27001 / FCA / HIPAA / PCI DSS / other)
- Organisation type (SaaS / fintech / healthcare / professional services / retail)
- Organisation size (startup / scaleup / mid-market / enterprise)
- Current maturity (no compliance programme / some controls / formal programme)
- Deadline or driver (upcoming audit / customer requirement / regulatory change / proactive)
Output Structure
1. Framework Overview
Framework: [Name with version] Applicable because: [One sentence — why this framework applies to this organisation] Typical timeline to readiness: [From current maturity to certified/compliant] Key stakeholders needed: [Roles that must be involved]
2. Scope Definition
What is in scope for this checklist:
- [Specific systems / processes / data types]
What is NOT in scope (explicit exclusions):
- [Specific exclusions]
3. Control Categories
For each category relevant to the framework:
[Category — e.g. "Access Control"]
| Control | Current State | Gap | Priority | Effort |
|---|---|---|---|---|
| [Specific control requirement] | Not implemented / Partial / Full | [What is missing] | High/Med/Low | Days/Weeks/Months |
4. Gap Analysis Summary
| Priority | Count | Examples |
|---|---|---|
| Critical gaps (block certification) | N | [Top 3] |
| High priority gaps | N | |
| Medium priority gaps | N | |
| Quick wins | N |
5. Quick Wins
Controls that can be implemented in under 2 weeks with minimal resources:
- [Control] — [Specific action] — [Owner] — [Days to complete]
6. Evidence Requirements
For each control area, what documentation will be needed:
| Control area | Evidence types | Where to source |
|---|---|---|
| [Area] | [Policies, logs, screenshots, training records] | [System or team] |
7. Implementation Roadmap
Phase 1 (Weeks 1-4): Critical gaps and quick wins
- [Specific deliverables]
Phase 2 (Weeks 5-12): High-priority gaps
- [Specific deliverables]
Phase 3 (Weeks 13+): Medium priority and continuous improvement
- [Specific deliverables]
8. Ongoing Maintenance
Once certified/compliant, what needs to continue:
- [Review frequencies]
- [Periodic testing requirements]
- [Annual audit expectations]
- [Staff training cadence]
9. Common Pitfalls for This Framework
2-3 specific traps organisations commonly fall into when pursuing this certification — flagged based on the stated maturity level.
Quality Checks
- Disclaimer included at start
- Framework-specific controls (not generic)
- Priorities align with organisation size and maturity
- Quick wins clearly separated from complex implementations
- Evidence requirements tied to specific controls
Anti-Patterns
- Do not omit the legal disclaimer — this checklist does not constitute compliance advice and must never be presented as a substitute for qualified professional review
- Do not generate a generic checklist that is not tailored to the stated framework, organisation type, and maturity level — a SOC 2 checklist for a startup and an enterprise are fundamentally different documents
- Do not list controls without specifying what evidence is required — a control without evidence requirements cannot be audited
- Do not mark a control as "full" implementation when it is partial — overestimating readiness leads to audit failures and regulatory risk
- Do not skip the "common pitfalls" section — this is where organisations most frequently fail audits for the stated framework
Example Trigger Phrases
- "Create a GDPR compliance checklist for our SaaS"
- "Generate a SOC 2 Type II readiness checklist"
- "What do we need for ISO 27001 certification?"
- "FCA compliance checklist for a fintech startup"
- "HIPAA gap analysis for a healthtech scaleup"
| 1 | |
| 2 | name compliance-checklist |
| 3 | description "Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis. Use when asked for a compliance checklist, gap analysis, readiness assessment, or audit preparation for any regulatory framework. Produces a structured checklist with prioritised gaps, quick wins, and evidence requirements. Optimised for Opus 4.7 and newer models. Not a substitute for legal or compliance professional advice." |
| 4 | |
| 5 | |
| 6 | # Compliance Checklist Skill |
| 7 | |
| 8 | Produces a prioritised compliance checklist for any regulatory framework — with gap analysis, evidence requirements, and quick wins identified. |
| 9 | |
| 10 | ALWAYS include this disclaimer at the start of every response: |
| 11 | "WARNING: This checklist is for informational and planning purposes only and does not constitute legal or compliance advice. Regulatory requirements change and vary by jurisdiction. Always engage a qualified compliance professional or solicitor before implementing compliance programmes or making regulatory claims." |
| 12 | |
| 13 | ## Required Inputs |
| 14 | |
| 15 | Ask the user for these if not provided: |
| 16 | **Framework** (GDPR / SOC 2 Type I or II / ISO 27001 / FCA / HIPAA / PCI DSS / other) |
| 17 | **Organisation type** (SaaS / fintech / healthcare / professional services / retail) |
| 18 | **Organisation size** (startup / scaleup / mid-market / enterprise) |
| 19 | **Current maturity** (no compliance programme / some controls / formal programme) |
| 20 | **Deadline or driver** (upcoming audit / customer requirement / regulatory change / proactive) |
| 21 | |
| 22 | ## Output Structure |
| 23 | |
| 24 | ### 1. Framework Overview |
| 25 | |
| 26 | **Framework:** [Name with version] |
| 27 | **Applicable because:** [One sentence — why this framework applies to this organisation] |
| 28 | **Typical timeline to readiness:** [From current maturity to certified/compliant] |
| 29 | **Key stakeholders needed:** [Roles that must be involved] |
| 30 | |
| 31 | ### 2. Scope Definition |
| 32 | |
| 33 | What is in scope for this checklist: |
| 34 | [Specific systems / processes / data types] |
| 35 | |
| 36 | What is NOT in scope (explicit exclusions): |
| 37 | [Specific exclusions] |
| 38 | |
| 39 | ### 3. Control Categories |
| 40 | |
| 41 | For each category relevant to the framework: |
| 42 | |
| 43 | **[Category — e.g. "Access Control"]** |
| 44 | |
| 45 | | Control | Current State | Gap | Priority | Effort | |
| 46 | |---|---|---|---|---| |
| 47 | | [Specific control requirement] | Not implemented / Partial / Full | [What is missing] | High/Med/Low | Days/Weeks/Months | |
| 48 | |
| 49 | ### 4. Gap Analysis Summary |
| 50 | |
| 51 | | Priority | Count | Examples | |
| 52 | |---|---|---| |
| 53 | | Critical gaps (block certification) | N | [Top 3] | |
| 54 | | High priority gaps | N | | |
| 55 | | Medium priority gaps | N | | |
| 56 | | Quick wins | N | | |
| 57 | |
| 58 | ### 5. Quick Wins |
| 59 | |
| 60 | Controls that can be implemented in under 2 weeks with minimal resources: |
| 61 | |
| 62 | **[Control]** — [Specific action] — [Owner] — [Days to complete] |
| 63 | |
| 64 | ### 6. Evidence Requirements |
| 65 | |
| 66 | For each control area, what documentation will be needed: |
| 67 | |
| 68 | | Control area | Evidence types | Where to source | |
| 69 | |---|---|---| |
| 70 | | [Area] | [Policies, logs, screenshots, training records] | [System or team] | |
| 71 | |
| 72 | ### 7. Implementation Roadmap |
| 73 | |
| 74 | Phase 1 (Weeks 1-4): Critical gaps and quick wins |
| 75 | [Specific deliverables] |
| 76 | |
| 77 | Phase 2 (Weeks 5-12): High-priority gaps |
| 78 | [Specific deliverables] |
| 79 | |
| 80 | Phase 3 (Weeks 13+): Medium priority and continuous improvement |
| 81 | [Specific deliverables] |
| 82 | |
| 83 | ### 8. Ongoing Maintenance |
| 84 | |
| 85 | Once certified/compliant, what needs to continue: |
| 86 | [Review frequencies] |
| 87 | [Periodic testing requirements] |
| 88 | [Annual audit expectations] |
| 89 | [Staff training cadence] |
| 90 | |
| 91 | ### 9. Common Pitfalls for This Framework |
| 92 | |
| 93 | 2-3 specific traps organisations commonly fall into when pursuing this certification — flagged based on the stated maturity level. |
| 94 | |
| 95 | ## Quality Checks |
| 96 | [ ] Disclaimer included at start |
| 97 | [ ] Framework-specific controls (not generic) |
| 98 | [ ] Priorities align with organisation size and maturity |
| 99 | [ ] Quick wins clearly separated from complex implementations |
| 100 | [ ] Evidence requirements tied to specific controls |
| 101 | |
| 102 | ## Anti-Patterns |
| 103 | |
| 104 | [ ] Do not omit the legal disclaimer — this checklist does not constitute compliance advice and must never be presented as a substitute for qualified professional review |
| 105 | [ ] Do not generate a generic checklist that is not tailored to the stated framework, organisation type, and maturity level — a SOC 2 checklist for a startup and an enterprise are fundamentally different documents |
| 106 | [ ] Do not list controls without specifying what evidence is required — a control without evidence requirements cannot be audited |
| 107 | [ ] Do not mark a control as "full" implementation when it is partial — overestimating readiness leads to audit failures and regulatory risk |
| 108 | [ ] Do not skip the "common pitfalls" section — this is where organisations most frequently fail audits for the stated framework |
| 109 | |
| 110 | ## Example Trigger Phrases |
| 111 | "Create a GDPR compliance checklist for our SaaS" |
| 112 | "Generate a SOC 2 Type II readiness checklist" |
| 113 | "What do we need for ISO 27001 certification?" |
| 114 | "FCA compliance checklist for a fintech startup" |
| 115 | "HIPAA gap analysis for a healthtech scaleup" |
Discussion
Browse more free Claude skills or everything in Legal & compliance.


