9 compliance frameworks as Claude skills — ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA, ISO 42001. 94% eval pass vs 72% baseline.
A GRC-focused skill library: one SKILL.md per framework with gap assessments, policy templates with citations, control implementation guidance, and audit-evidence checklists. Covers both ISO 27001 2013 and 2022 versions, SOC 2 trust criteria, FedRAMP via NIST SP 800-53 Rev 5, and the ISO 42001 AI Management System.
Когда использовать: You're building a PHI-handling service and need to map each HIPAA safeguard.
Поток
Current controls inventory
Use the HIPAA skill. Here's our tech stack and current controls [paste]. Map to Security Rule administrative, physical, technical safeguards.✓ Скопировано
→ Safeguard-by-safeguard mapping with gaps flagged
Breach-Notification-readiness plan
What do we need for a compliant breach-notification workflow?✓ Скопировано
→ Runbook with timelines and responsible roles
Итог: A HIPAA control matrix plus breach-readiness runbook.
Подводные камни
Assuming BAA = full compliance — Skill distinguishes BAA scope from the broader Security Rule