# Grc Compliance Privacy Program

> Use for governance, risk, compliance, privacy, audit readiness, control mapping, SOC 2, ISO 27001, NIST CSF, CIS, GDPR, legal/regulatory scoping, policy evidence, vendor risk, and security program maturity work.

- Skill: `26zl/grc-compliance-privacy-program` (Agent Skill)
- Install (CLI): `npx skillmds@latest add 26zl/grc-compliance-privacy-program`
- Raw SKILL.md: https://api.skillmd.com/api/skills/26zl/grc-compliance-privacy-program/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: 26zl (https://skillmd.com/u/26zl)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/26zl/grc-compliance-privacy-program

---


# GRC, compliance, and privacy program workflow

Use this skill when the task is about proving security, governing risk, mapping controls, privacy obligations, audit readiness, or legal/regulatory scoping.

## Guardrails

- Do not provide legal advice. For region-specific legal obligations, check current official sources and recommend counsel review.
- Do not claim certification, compliance, or audit pass/fail without evidence from the user's environment.
- Prefer control intent, evidence, owner, frequency, and test procedure over vague policy language.

## Workflow

1. Scope the organization, jurisdiction, sector, data classes, systems, third parties, and target frameworks.
2. Build a control crosswalk only for relevant frameworks; avoid mapping everything to everything.
3. For each control, define:
   - control objective
   - owner
   - implementation evidence
   - operating evidence
   - test method
   - cadence
   - gap/risk
4. Separate policy existence from operational effectiveness.
5. Produce a remediation plan with risk, effort, owner, and evidence needed to close.

## Output pattern

Use a table like:

| Area | Requirement | Current evidence | Gap | Risk | Owner | Next action |
| --- | --- | --- | --- | --- | --- | --- |

For privacy work, include data inventory, lawful basis/processing purpose, retention, access, transfer, processor/subprocessor, DSAR, deletion, breach notification, and logging requirements.

