Compliance Checklist Skill

Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis.

Compliance Checklist Skill — The Skill Playground: pick the Executive Update skill, fill in a few notes, hit run, and watch a structured executive… (from the mohitagw15856/pm-claude-skills README)

From the mohitagw15856/pm-claude-skills README — shows the whole collection, not only this skill. · view on GitHub

How to use it

Claude Code
  1. Run the line below. It pulls the whole folder into ~/.claude/skills/compliance-checklist.
  2. Describe your job in plain words. Claude Code follows the skill from there.
Claude Code — installs the whole folder, not just SKILL.md
npx degit mohitagw15856/pm-claude-skills/skills/compliance-checklist#main ~/.claude/skills/compliance-checklist

For one project only, change the path to .claude/skills/compliance-checklist.

Claude (web or desktop app)
  1. On this page open ⋯ → Download .md.
  2. Save it as SKILL.md in a folder, zip the folder, then Customize → Skills → + → Create skill → Upload a skill.
  3. Pick the file and Save. Claude shows the name and description and runs a security scan.
  4. Check the skill is switched on.
  5. Start a new chat and describe your job in plain words. The AI follows the skill from there.
ChatGPT or another app
  1. ChatGPT: make a Project and paste it into Instructions.
  2. Neither? Paste it at the top of a new chat — it works for that chat.
Not working?
  • Check which app you pasted it into — the steps above name the right one.
  • Some skills need the paid tier of Claude or ChatGPT.
Step-by-step guide with screenshots · Ask in the forum

Paste into Claude, ChatGPT or Cursor.

Source of Compliance Checklist Skill

Show the full text115 lines
namedescription
compliance-checklistGenerate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis. Use when asked for a compliance checklist, gap analysis, readiness assessment, or audit preparation for any regulatory framework. Produces a structured checklist with prioritised gaps, quick wins, and evidence requirements. Optimised for Opus 4.7 and newer models. Not a substitute for legal or compliance professional advice.

Compliance Checklist Skill

Produces a prioritised compliance checklist for any regulatory framework — with gap analysis, evidence requirements, and quick wins identified.

ALWAYS include this disclaimer at the start of every response: "WARNING: This checklist is for informational and planning purposes only and does not constitute legal or compliance advice. Regulatory requirements change and vary by jurisdiction. Always engage a qualified compliance professional or solicitor before implementing compliance programmes or making regulatory claims."

Required Inputs

Ask the user for these if not provided:

  • Framework (GDPR / SOC 2 Type I or II / ISO 27001 / FCA / HIPAA / PCI DSS / other)
  • Organisation type (SaaS / fintech / healthcare / professional services / retail)
  • Organisation size (startup / scaleup / mid-market / enterprise)
  • Current maturity (no compliance programme / some controls / formal programme)
  • Deadline or driver (upcoming audit / customer requirement / regulatory change / proactive)

Output Structure

1. Framework Overview

Framework: [Name with version] Applicable because: [One sentence — why this framework applies to this organisation] Typical timeline to readiness: [From current maturity to certified/compliant] Key stakeholders needed: [Roles that must be involved]

2. Scope Definition

What is in scope for this checklist:

  • [Specific systems / processes / data types]

What is NOT in scope (explicit exclusions):

  • [Specific exclusions]
3. Control Categories

For each category relevant to the framework:

[Category — e.g. "Access Control"]

Control Current State Gap Priority Effort
[Specific control requirement] Not implemented / Partial / Full [What is missing] High/Med/Low Days/Weeks/Months
4. Gap Analysis Summary
Priority Count Examples
Critical gaps (block certification) N [Top 3]
High priority gaps N
Medium priority gaps N
Quick wins N
5. Quick Wins

Controls that can be implemented in under 2 weeks with minimal resources:

  1. [Control] — [Specific action] — [Owner] — [Days to complete]
6. Evidence Requirements

For each control area, what documentation will be needed:

Control area Evidence types Where to source
[Area] [Policies, logs, screenshots, training records] [System or team]
7. Implementation Roadmap

Phase 1 (Weeks 1-4): Critical gaps and quick wins

  • [Specific deliverables]

Phase 2 (Weeks 5-12): High-priority gaps

  • [Specific deliverables]

Phase 3 (Weeks 13+): Medium priority and continuous improvement

  • [Specific deliverables]
8. Ongoing Maintenance

Once certified/compliant, what needs to continue:

  • [Review frequencies]
  • [Periodic testing requirements]
  • [Annual audit expectations]
  • [Staff training cadence]
9. Common Pitfalls for This Framework

2-3 specific traps organisations commonly fall into when pursuing this certification — flagged based on the stated maturity level.

Quality Checks

  • Disclaimer included at start
  • Framework-specific controls (not generic)
  • Priorities align with organisation size and maturity
  • Quick wins clearly separated from complex implementations
  • Evidence requirements tied to specific controls

Anti-Patterns

  • Do not omit the legal disclaimer — this checklist does not constitute compliance advice and must never be presented as a substitute for qualified professional review
  • Do not generate a generic checklist that is not tailored to the stated framework, organisation type, and maturity level — a SOC 2 checklist for a startup and an enterprise are fundamentally different documents
  • Do not list controls without specifying what evidence is required — a control without evidence requirements cannot be audited
  • Do not mark a control as "full" implementation when it is partial — overestimating readiness leads to audit failures and regulatory risk
  • Do not skip the "common pitfalls" section — this is where organisations most frequently fail audits for the stated framework

Example Trigger Phrases

  • "Create a GDPR compliance checklist for our SaaS"
  • "Generate a SOC 2 Type II readiness checklist"
  • "What do we need for ISO 27001 certification?"
  • "FCA compliance checklist for a fintech startup"
  • "HIPAA gap analysis for a healthtech scaleup"
1---
2name: compliance-checklist
3description: "Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis. Use when asked for a compliance checklist, gap analysis, readiness assessment, or audit preparation for any regulatory framework. Produces a structured checklist with prioritised gaps, quick wins, and evidence requirements. Optimised for Opus 4.7 and newer models. Not a substitute for legal or compliance professional advice."
4---
5 
6# Compliance Checklist Skill
7 
8Produces a prioritised compliance checklist for any regulatory framework — with gap analysis, evidence requirements, and quick wins identified.
9 
10ALWAYS include this disclaimer at the start of every response:
11"WARNING: This checklist is for informational and planning purposes only and does not constitute legal or compliance advice. Regulatory requirements change and vary by jurisdiction. Always engage a qualified compliance professional or solicitor before implementing compliance programmes or making regulatory claims."
12 
13## Required Inputs
14 
15Ask the user for these if not provided:
16- **Framework** (GDPR / SOC 2 Type I or II / ISO 27001 / FCA / HIPAA / PCI DSS / other)
17- **Organisation type** (SaaS / fintech / healthcare / professional services / retail)
18- **Organisation size** (startup / scaleup / mid-market / enterprise)
19- **Current maturity** (no compliance programme / some controls / formal programme)
20- **Deadline or driver** (upcoming audit / customer requirement / regulatory change / proactive)
21 
22## Output Structure
23 
24### 1. Framework Overview
25 
26**Framework:** [Name with version]
27**Applicable because:** [One sentence — why this framework applies to this organisation]
28**Typical timeline to readiness:** [From current maturity to certified/compliant]
29**Key stakeholders needed:** [Roles that must be involved]
30 
31### 2. Scope Definition
32 
33What is in scope for this checklist:
34- [Specific systems / processes / data types]
35 
36What is NOT in scope (explicit exclusions):
37- [Specific exclusions]
38 
39### 3. Control Categories
40 
41For each category relevant to the framework:
42 
43**[Category — e.g. "Access Control"]**
44 
45| Control | Current State | Gap | Priority | Effort |
46|---|---|---|---|---|
47| [Specific control requirement] | Not implemented / Partial / Full | [What is missing] | High/Med/Low | Days/Weeks/Months |
48 
49### 4. Gap Analysis Summary
50 
51| Priority | Count | Examples |
52|---|---|---|
53| Critical gaps (block certification) | N | [Top 3] |
54| High priority gaps | N | |
55| Medium priority gaps | N | |
56| Quick wins | N | |
57 
58### 5. Quick Wins
59 
60Controls that can be implemented in under 2 weeks with minimal resources:
61 
621. **[Control]** — [Specific action] — [Owner] — [Days to complete]
63 
64### 6. Evidence Requirements
65 
66For each control area, what documentation will be needed:
67 
68| Control area | Evidence types | Where to source |
69|---|---|---|
70| [Area] | [Policies, logs, screenshots, training records] | [System or team] |
71 
72### 7. Implementation Roadmap
73 
74Phase 1 (Weeks 1-4): Critical gaps and quick wins
75- [Specific deliverables]
76 
77Phase 2 (Weeks 5-12): High-priority gaps
78- [Specific deliverables]
79 
80Phase 3 (Weeks 13+): Medium priority and continuous improvement
81- [Specific deliverables]
82 
83### 8. Ongoing Maintenance
84 
85Once certified/compliant, what needs to continue:
86- [Review frequencies]
87- [Periodic testing requirements]
88- [Annual audit expectations]
89- [Staff training cadence]
90 
91### 9. Common Pitfalls for This Framework
92 
932-3 specific traps organisations commonly fall into when pursuing this certification — flagged based on the stated maturity level.
94 
95## Quality Checks
96- [ ] Disclaimer included at start
97- [ ] Framework-specific controls (not generic)
98- [ ] Priorities align with organisation size and maturity
99- [ ] Quick wins clearly separated from complex implementations
100- [ ] Evidence requirements tied to specific controls
101 
102## Anti-Patterns
103 
104- [ ] Do not omit the legal disclaimer — this checklist does not constitute compliance advice and must never be presented as a substitute for qualified professional review
105- [ ] Do not generate a generic checklist that is not tailored to the stated framework, organisation type, and maturity level — a SOC 2 checklist for a startup and an enterprise are fundamentally different documents
106- [ ] Do not list controls without specifying what evidence is required — a control without evidence requirements cannot be audited
107- [ ] Do not mark a control as "full" implementation when it is partial — overestimating readiness leads to audit failures and regulatory risk
108- [ ] Do not skip the "common pitfalls" section — this is where organisations most frequently fail audits for the stated framework
109 
110## Example Trigger Phrases
111- "Create a GDPR compliance checklist for our SaaS"
112- "Generate a SOC 2 Type II readiness checklist"
113- "What do we need for ISO 27001 certification?"
114- "FCA compliance checklist for a fintech startup"
115- "HIPAA gap analysis for a healthtech scaleup"

Discussion

Alternatives

Also in Regulation & privacySee all 23 in Legal & compliance →
Gdpr data handlingImplement GDPR-compliant data handling with consent management, data subject rights, and privacy by design. Use when building systems that process EU personal data, implementing privacy controls, or conducting GDPR compliance reviews.Business & ops · MITPci complianceImplement PCI DSS compliance requirements for secure handling of payment card data and payment systems. Use when securing payment processing, achieving PCI compliance, or implementing payment card security measures.Business & ops · MIT/cs:ciso-review — CISO Forcing Questions/cs:ciso-review <plan> — Risk-paranoid interrogation of any plan that touches data, compliance, or production access. Use when launching features that handle customer data, before a SOC 2 / ISO audit, or after any incident or near-miss.Business & ops · MITCompliance OS — Meta-OrchestratorCompliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across multiple frameworks. Four decisions: (1) Given a company profile, which of the 12 supported frameworks apply (ISO 27001/13485/42001/14971, EU AI Act, MDR 745, GDPR, SOC 2, FDA QSR, NIST CSF 2.0, NIS2, HIPAA)? (2) Across selected frameworks, which controls overlap and how much evidence reuses? (3) For a given framework + scope, what does a realistic mock audit produce — drawing from the 205-scenario library? (4) Across selected frameworks, what's the unified evidence checklist with reuse map? Use when standing up a multi-framework program, planning the annual audit calendar, or preparing for certification stage 1. Does NOT replace per-framework skills (it orchestrates them).Business & ops · MIT