global-grc

Map security controls against mid-2026 regulatory requirements across 14 jurisdictions.

Updated May 11, 2026
One-click install
npx skills add https://github.com/blamejs/exceptd-skills --skill global-grc
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: global-grc
Source: https://github.com/blamejs/exceptd-skills/tree/main/skills/global-grc
Command: npx skills add https://github.com/blamejs/exceptd-skills --skill global-grc

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Most security and compliance tools rely on stale, pre-2020 threat models and framework documentation that fails to address mid-2026 attack patterns like prompt injection, MCP supply chain attacks, and AI-as-C2. Organizations operating across multiple jurisdictions struggle to map their existing controls to global regulatory requirements, leading to critical compliance gaps, unexpected fines, and unaddressed threat coverage.

Core Features & Use Cases

  • Multi-Jurisdiction Framework Mapping: Covers 14 jurisdictions (EU, UK, AU, SG, JP, IN, CA, etc.) and 2 global standards (ISO 27001:2022, CSA CCM v4) with up-to-date mid-2026 regulatory requirements.
  • Universal Control Gap Identification: Surfaces 8+ critical control gaps unaddressed by any national or global framework, including prompt injection as an access control failure, MCP/agent trust boundaries, and AI pipeline integrity requirements.
  • Notification & Compliance Timeline Summaries: Provides side-by-side comparison of incident notification timelines, patch SLAs, and enforcement penalties across all covered jurisdictions.
  • Use Case: A global financial services firm can use this skill to quickly identify that its existing NIST-based compliance program misses NIS2 24-hour early-warning incident notification requirements and EU AI Act Art. 9 risk management obligations for high-risk AI systems.

Quick Start

Use the global-grc skill to map your organization's current security controls against EU NIS2 and DORA requirements to identify all compliance gaps for mid-2026 threat patterns.

Frequently Asked Questions about global-grc

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map existing security controls against global regulatory requirements like EU NIS2 and DORA?

To map security controls against global regulatory requirements, align your existing frameworks with mid-2026 threat reality across 14+ jurisdictions. This identifies critical compliance gaps, including missed incident notification timelines and AI risk management obligations for global enterprises.

What compliance frameworks are covered for cross-border regulatory gap analysis?

Cross-border regulatory gap analysis covers 14 jurisdictions including EU, UK, AU, SG, JP, IN, and CA, alongside 2 global standards: ISO 27001:2022 and CSA CCM v4. This provides side-by-side comparison of incident notification timelines and enforcement penalties.

How do I identify unaddressed AI threat control gaps like prompt injection in my compliance program?

Identify unaddressed AI threat control gaps by surfacing 8+ critical vulnerabilities missing from national or global frameworks. This includes detecting prompt injection access control failures, MCP/agent trust boundary issues, and AI pipeline integrity requirements.

Does this compliance assessment support incident notification timeline comparisons across multiple jurisdictions?

Yes, the compliance assessment supports incident notification timeline comparisons. It provides side-by-side summaries of incident notification deadlines, patch SLAs, and enforcement penalties across all 14+ covered global jurisdictions.

Can I use this to check if my NIST-based compliance program misses EU AI Act risk management obligations?

Yes, you can use this to check if your NIST-based compliance program misses EU AI Act Article 9 risk management obligations. It maps your current controls against mid-2026 regulatory requirements to quickly identify unaddressed high-risk AI system obligations.

What are the limitations of using pre-2020 threat models for multi-jurisdiction compliance?

Pre-2020 threat models fail to address mid-2026 attack patterns like MCP supply chain attacks and AI-as-C2. Relying on stale framework documentation leads to critical compliance gaps and unexpected fines across multi-jurisdiction operations.