What problem does it solve?
Companies running two or more compliance frameworks (ISO 27001, SOC 2, GDPR, EU AI Act, HIPAA, etc.) in parallel waste effort on duplicate evidence collection, conflicting audit calendars, and fragmented management reviews. This Skill provides a meta-orchestration layer that determines which of 12 supported frameworks apply to a company, computes cross-framework control overlap, simulates internal audits, and consolidates a unified evidence pool.
Core Features & Use Cases
- Framework Selection: Ranks 12 frameworks (ISO 27001/13485/42001/14971, EU AI Act, MDR 745, GDPR, SOC 2, FDA QSR, NIST CSF 2.0, NIS2, HIPAA) against a company profile JSON and returns applicable ones with a dependency graph.
- Cross-Framework Control Mapping: Computes control-level overlap with HIGH/MEDIUM/LOW confidence ratings and identifies evidence-reuse opportunities across enabled frameworks.
- Audit Simulation: Generates realistic mock internal audits per ISO 19011 and IIA IPPF with 8-15 findings, healthy severity distribution, interview questions, and document-review requests, drawing on a 205-scenario library.
- Evidence Pool Consolidation: Produces a unified evidence checklist showing which artefact satisfies which controls across which frameworks, with reuse-leverage scoring.
- Use Case: A mid-stage AI SaaS company selling to EU enterprise customers runs the framework selector, learns it needs ISO 27001 + SOC 2 + ISO 42001 + EU AI Act + GDPR, then maps overlap to discover that one quarterly access-review record satisfies controls in all five frameworks.
Quick Start
Ask the assistant to run the compliance-os framework selector against your company profile JSON to determine which compliance frameworks apply and how their controls overlap.