Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO 27701, DORA, CSRD, India's DPDPA, CMMC 2.0, NIST AI Risk, SWIFT, CCPA/CPRA, and others. Benchmark 93% (with skills) vs 79% (without skills). Updated Monthly.

What it solves

This project provides a collection of specialized knowledge packages called "Claude Skills" designed to help professionals navigate complex Governance, Risk, and Compliance (GRC) frameworks. It reduces the time spent on manual reference work, gap assessments, and drafting regulatory documentation for dozens of global standards such as ISO 27001, SOC 2, GDPR, and HIPAA.

How it works

Each skill is delivered as a .skill file (a bundled archive containing instructions and reference materials) that is uploaded to Claude. These skills use a "progressive disclosure" pattern, where a primary instruction file is loaded into context and deeper reference materials are loaded on demand. Once installed, the skills activate automatically when the conversation topic matches the skill's domain, turning Claude into a domain-specific expert without requiring manual invocation.

Who it’s for

  • Security & Compliance Teams: For accelerating gap assessments and preparing evidence packages.
  • Software Developers & Engineers: For auditing code and architecture against regulatory requirements.
  • Legal & Privacy Professionals: For drafting regulatory documents like DPAs and privacy notices.
  • Healthcare & Cloud Providers: For managing specific obligations like HIPAA or FedRAMP ATO processes.
  • Startups & SMBs: For scoping compliance programs without a large in-house team.

Highlights

  • Broad Framework Coverage: Supports over 30 standards including ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, and the EU AI Act.
  • High Accuracy: Benchmarked at 94% accuracy across 150 test cases using an independent agent evaluation framework.
  • Audit-Ready Output: Generates professional policy templates, control narratives, and risk registers.
  • Automated Activation: Skills trigger automatically based on conversation context.

Related

  • Project
  • Project
  • Project
  • Project
  • Project