CC
Compliance Checklist
🔵 Stable🕐 updated 2026-06-08
🔷 SkillSpec L3
pm-legal
Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis. Use when asked for a compliance checklist, gap analysis, readiness assessment, or audit preparation for any regulatory framework. Produces a structured checklist with prioritised gaps, quick wins, and evidence requirements. Optimised for Opus 4.7 and newer models. Not a substitute for legal or compliance professional advice.
🗣 Say this to your agent
“Create a GDPR compliance checklist for our SaaS”“Generate a SOC 2 Type II readiness checklist”“What do we need for ISO 27001 certification?”“FCA compliance checklist for a fintech startup”“HIPAA gap analysis for a healthtech scaleup”
What to give it
▸Framework — GDPR / SOC 2 Type I or II / ISO 27001 / FCA / HIPAA / PCI DSS / other
▸Organisation type — SaaS / fintech / healthcare / professional services / retail
▸Organisation size — startup / scaleup / mid-market / enterprise
▸Current maturity — no compliance programme / some controls / formal programme
▸Deadline or driver — upcoming audit / customer requirement / regulatory change / proactive
✅ The bar it holds itself to
Every skill in this library self-verifies — these are this skill's own quality checks, straight from its definition.
✓Disclaimer included at start
✓Framework-specific controls (not generic)
✓Priorities align with organisation size and maturity
✓Quick wins clearly separated from complex implementations
✓Evidence requirements tied to specific controls
⚠️ What it refuses to do
Do not omit the legal disclaimer — this checklist does not constitute compliance advice and must never be presented as a substitute for qualified professional review
Do not generate a generic checklist that is not tailored to the stated framework, organisation type, and maturity level — a SOC 2 checklist for a startup and an enterprise are fundamentally different documents
Do not list controls without specifying what evidence is required — a control without evidence requirements cannot be audited
Do not mark a control as "full" implementation when it is partial — overestimating readiness leads to audit failures and regulatory risk
Do not skip the "common pitfalls" section — this is where organisations most frequently fail audits for the stated framework
Install
npx pm-claude-skills add --agent claude # or codex · cursor · gemini · hermes
# or one-line MCP (every skill, any client):
claude mcp add pm-skills -- npx -y pm-claude-skills-mcp
Start with
Related skills
🔌 Embed this skill
Drop this on your blog, docs, or site — it renders a "Run this skill" card:
<div data-pm-skill="compliance-checklist"></div>
<script src="https://mohitagw15856.github.io/pm-claude-skills/embed.js" async></script>
💬 Discussion
Compliance Checklist is one of 1153 open-source professional AI agent skills — all SkillSpec L3.
Try them all in the browser · ⭐ Star on GitHub · Browse the full catalog