GRC, compliance, and privacy program workflow
Use this skill when the task is about proving security, governing risk, mapping controls, privacy obligations, audit readiness, or legal/regulatory scoping.
Guardrails
- Do not provide legal advice. For region-specific legal obligations, check current official sources and recommend counsel review.
- Do not claim certification, compliance, or audit pass/fail without evidence from the user's environment.
- Prefer control intent, evidence, owner, frequency, and test procedure over vague policy language.
Workflow
- Scope the organization, jurisdiction, sector, data classes, systems, third parties, and target frameworks.
- Build a control crosswalk only for relevant frameworks; avoid mapping everything to everything.
- For each control, define:
- control objective
- owner
- implementation evidence
- operating evidence
- test method
- cadence
- gap/risk
- Separate policy existence from operational effectiveness.
- Produce a remediation plan with risk, effort, owner, and evidence needed to close.
Output pattern
Use a table like:
| Area |
Requirement |
Current evidence |
Gap |
Risk |
Owner |
Next action |
For privacy work, include data inventory, lawful basis/processing purpose, retention, access, transfer, processor/subprocessor, DSAR, deletion, breach notification, and logging requirements.
1---2name: grc-compliance-privacy-program3description: Use for governance, risk, compliance, privacy, audit readiness, control mapping, SOC 2, ISO 27001, NIST CSF, CIS, GDPR, legal/regulatory scoping, policy evidence, vendor risk, and security program maturity work.4---56# GRC, compliance, and privacy program workflow78Use this skill when the task is about proving security, governing risk, mapping controls, privacy obligations, audit readiness, or legal/regulatory scoping.910## Guardrails1112- Do not provide legal advice. For region-specific legal obligations, check current official sources and recommend counsel review.13- Do not claim certification, compliance, or audit pass/fail without evidence from the user's environment.14- Prefer control intent, evidence, owner, frequency, and test procedure over vague policy language.1516## Workflow17181. Scope the organization, jurisdiction, sector, data classes, systems, third parties, and target frameworks.192. Build a control crosswalk only for relevant frameworks; avoid mapping everything to everything.203. For each control, define:21 - control objective22 - owner23 - implementation evidence24 - operating evidence25 - test method26 - cadence27 - gap/risk284. Separate policy existence from operational effectiveness.295. Produce a remediation plan with risk, effort, owner, and evidence needed to close.3031## Output pattern3233Use a table like:3435| Area | Requirement | Current evidence | Gap | Risk | Owner | Next action |36| --- | --- | --- | --- | --- | --- | --- |3738For privacy work, include data inventory, lawful basis/processing purpose, retention, access, transfer, processor/subprocessor, DSAR, deletion, breach notification, and logging requirements.