compliance_analyst

Guides certification research, gap analysis, and regulatory compliance workflows for standards like GDPR and SOC 2.

Updated Jan 14, 2026
One-click install
npx skills add https://github.com/jvsandhu/agentic-skills --skill compliance-analyst-jvsandhu
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: compliance_analyst
Source: https://github.com/jvsandhu/agentic-skills/tree/main/skills/compliance_analyst
Command: npx skills add https://github.com/jvsandhu/agentic-skills --skill compliance-analyst-jvsandhu

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Navigating certification requirements and regulatory frameworks like GDPR, SOC 2, ISO 27001, and the EU AI Act is complex and error-prone. This Skill provides structured checklists, gap analysis templates, and phased workflows to assess and achieve compliance. ## Core Features & Use Cases - Compliance Checklists: Ready-made checklists for GDPR (consent management, right to deletion, breach notification) and SOC 2 (security controls, availability SLA, confidentiality). - Gap Analysis Template: A structured Markdown template to compare required controls against current state and build remediation plans with owners and deadlines. - Phased Workflow: A three-phase process covering regulatory scoping (DORA, NIS2, EU AI Act risk categorization), audit and gap assessment, and remediation with continuous monitoring. - Use Case: A team preparing for SOC 2 certification uses the gap analysis template to identify missing audit logging, assigns remediation to DevOps, and tracks progress toward an audit-ready file. ## Quick Start Ask the agent to run a GDPR compliance gap analysis on your current data processing practices and produce a remediation plan.

Frequently Asked Questions about compliance_analyst

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a GDPR compliance gap analysis?

Use the provided gap analysis template to map required GDPR controls against your current state, marking each as compliant, partial, or missing. Then build a remediation plan assigning each gap an action, owner, and deadline, typically spanning three months of remediation before audit preparation.

What is the difference between SOC 2 and ISO 27001 compliance?

SOC 2 focuses on trust service criteria like security, availability, processing integrity, confidentiality, and privacy, verified through an auditor's report. ISO 27001 is an international standard for information security management systems. This Skill covers checklists and workflows applicable to both.

How are AI systems classified under the EU AI Act?

The EU AI Act classifies AI systems into four risk levels: Unacceptable, High, Limited, and Minimal. The Skill's Phase 1 workflow guides risk categorization to determine which obligations apply to your system before proceeding to gap assessment.

How long does compliance certification typically take?

The certification path from assessment through gap analysis, remediation, and audit typically takes 6 to 12 months. A common breakdown is three months for gap remediation, one month for audit preparation, and two months for the certification process itself.

What evidence is needed for a compliance audit?

Audits require policy documents, log records, system configurations, and an up-to-date record of processing activities (ROPA). The Skill's Phase 2 workflow covers evidence collection and preparing an audit-ready file for independent auditors.